Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15201-15220 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-24961 - Wordpress File Upload Plugin

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Wordpress File Upload

CVE-2021-24961

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24960 - Before 4 Plugin

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2021-24960

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24826 - Custom Content Shortcode Plugin

The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when the unfiltered_html is disallowed)

PLUGIN Custom Content Shortcode

CVE-2021-24826

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24821 - Cost Calculator Plugin

The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as well as the Text Preview field of a Project (injected on the edit project page)

PLUGIN Cost Calculator

CVE-2021-24821

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-25009 - Correosexpress Plugin

The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses

PLUGIN Correosexpress

CVE-2021-25009

MEDIUM CVSS 5.3 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24825 - Custom Content Shortcode Plugin

The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP files will be executed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when either the unfiltered_html or file_edit is disallowed)

PLUGIN Custom Content Shortcode

CVE-2021-24825

MEDIUM CVSS 4.3 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24824 - Shortcode Included With The Custom Content Shortcode Plugin

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved

PLUGIN Shortcode Included With The Custom Content Shortcode

CVE-2021-24824

MEDIUM CVSS 4.3 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24777 - View Submission Functionality In The Hotscot Contact Form Plugin

The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection.

PLUGIN View Submission Functionality In The Hotscot Contact Form

CVE-2021-24777

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24216 - All In One Wp Migration Plugin

The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.

PLUGIN All In One Wp Migration

CVE-2021-24216

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24810 - Wp Event Manager Plugin

The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Wp Event Manager

CVE-2021-24810

MEDIUM CVSS 4.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0412 - Before 1 Plugin

The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

PLUGIN Before 1

CVE-2022-0412

CRITICAL CVSS 9.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0411 - Asgaros Forum Plugin

The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection

PLUGIN Asgaros Forum

CVE-2022-0411

HIGH CVSS 8.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-23911 - Testimonial Plugin

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

PLUGIN Testimonial

CVE-2022-23911

HIGH CVSS 7.2 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0383 - Wp Review Slider Plugin

The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks

PLUGIN Wp Review Slider

CVE-2022-0383

HIGH CVSS 7.2 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-23988 - Ws Form Plugin

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

PLUGIN Ws Form

CVE-2022-23988

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-23912 - Testimonial Plugin

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting

PLUGIN Testimonial

CVE-2022-23912

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0385 - Crazy Bone Plugin

The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting

PLUGIN Crazy Bone

CVE-2022-0385

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-23987 - Ws Form Plugin

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Ws Form

CVE-2022-23987

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0360 - Wp Ultimate Csv Importer Plugin

The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues

PLUGIN Wp Ultimate Csv Importer

CVE-2022-0360

MEDIUM CVSS 4.8 2022-02-28
Scroll to top