Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15381-15400 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-25074 - Webp Converter For Media Plugin

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

PLUGIN Webp Converter For Media

CVE-2021-25074

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25031 - Before 9 Plugin

The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 9

CVE-2021-25031

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25028 - Event Tickets Plugin

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

PLUGIN Event Tickets

CVE-2021-25028

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25017 - Before 1 Plugin

The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-25017

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25015 - Mycred Plugin

The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Mycred

CVE-2021-25015

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25008 - Code Snippets Plugin

The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue

PLUGIN Code Snippets

CVE-2021-25008

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24985 - Before 6 Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 6

CVE-2021-24985

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24976 - Smart Seo Tool Plugin

The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting

PLUGIN Smart Seo Tool

CVE-2021-24976

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25049 - Mobile Events Manager Plugin

The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Mobile Events Manager

CVE-2021-25049

MEDIUM CVSS 4.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24696 - Simple Download Monitor Plugin

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads

PLUGIN Simple Download Monitor

CVE-2021-24696

HIGH CVSS 8.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24936 - Wp Extra File Types Plugin

The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

PLUGIN Wp Extra File Types

CVE-2021-24936

HIGH CVSS 8.0 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24906 - Protect Wp Admin Plugin

The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

PLUGIN Protect Wp Admin

CVE-2021-24906

HIGH CVSS 7.5 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24865 - Before 0 Plugin

The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue

PLUGIN Before 0

CVE-2021-24865

HIGH CVSS 7.2 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24858 - Cookie Notification Plugin

The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection

PLUGIN Cookie Notification

CVE-2021-24858

HIGH CVSS 7.2 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24968 - Before 2 Plugin

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

PLUGIN Before 2

CVE-2021-24968

MEDIUM CVSS 5.7 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24974 - Product Feed Pro For Woocommerce Plugin

The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.

PLUGIN Product Feed Pro For Woocommerce

CVE-2021-24974

MEDIUM CVSS 5.4 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24965 - Five Star Restaurant Reservations Plugin

The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins

PLUGIN Five Star Restaurant Reservations

CVE-2021-24965

MEDIUM CVSS 5.4 2022-01-24
Scroll to top