Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15441-15460 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2022-0233 - Profilegrid User Profiles Groups And Communities Plugin

The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7.

PLUGIN Profilegrid User Profiles Groups And Communities

CVE-2022-0233

MEDIUM CVSS 6.4 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2022-0232 - Custom Landing Pages Leadmagic Plugin

The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.2.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Custom Landing Pages Leadmagic

CVE-2022-0232

MEDIUM CVSS 4.8 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2022-0210 - Random Banner Plugin

The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Random Banner

CVE-2022-0210

MEDIUM CVSS 4.8 2022-01-18
Threat Entry Updated 2025-02-14

CVE-2021-43353 - Crisp Plugin

The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 0.31.

PLUGIN Crisp

CVE-2021-43353

HIGH CVSS 8.8 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2021-4074 - Whmcs Bridge Plugin

The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge_add_admin function, low-level authenticated users such as subscribers can exploit this vulnerability.

PLUGIN Whmcs Bridge

CVE-2021-4074

MEDIUM CVSS 6.4 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2021-25036 - All In One Seo Plugin

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.

PLUGIN All In One Seo

CVE-2021-25036

HIGH CVSS 8.8 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25037 - All In One Seo Plugin

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).

PLUGIN All In One Seo

CVE-2021-25037

MEDIUM CVSS 6.5 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25024 - Before 1 Plugin

The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

PLUGIN Before 1

CVE-2021-25024

MEDIUM CVSS 6.1 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-24909 - Acf Photo Gallery Field Plugin

The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Acf Photo Gallery Field

CVE-2021-24909

MEDIUM CVSS 6.1 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-24838 - Before 0 Plugin

The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

PLUGIN Before 0

CVE-2021-24838

MEDIUM CVSS 6.1 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25046 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

PLUGIN Modern Events Calendar Lite

CVE-2021-25046

MEDIUM CVSS 5.4 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25005 - Seur Oficial Plugin

The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Seur Oficial

CVE-2021-25005

MEDIUM CVSS 4.8 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25025 - Before 1 Plugin

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

PLUGIN Before 1

CVE-2021-25025

MEDIUM CVSS 4.3 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25054 - Wpcalc Plugin

The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.

PLUGIN Wpcalc

CVE-2021-25054

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25053 - Before 2 Plugin

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Before 2

CVE-2021-25053

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25052 - Before 2 Plugin

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Before 2

CVE-2021-25052

HIGH CVSS 8.8 2022-01-10
Scroll to top