Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15521-15540 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-39314 - Woo Enviopack Plugin

The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter found in the ~/includes/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

PLUGIN Woo Enviopack

CVE-2021-39314

MEDIUM CVSS 6.1 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-39313 - Simple Responsive Image Gallery Plugin

The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.

PLUGIN Simple Responsive Image Gallery

CVE-2021-39313

MEDIUM CVSS 6.1 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-39311 - Link List Manager Plugin

The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found in the ~/llm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

PLUGIN Link List Manager

CVE-2021-39311

MEDIUM CVSS 6.1 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-39310 - Real Wysiwyg Plugin

The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/real-wysiwyg.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.2.

PLUGIN Real Wysiwyg

CVE-2021-39310

MEDIUM CVSS 6.1 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-39309 - Parsian Bank Gateway For Woocommerce Plugin

The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parameter due to a var_dump() on $_POST variables found in the ~/vendor/dpsoft/parsian-payment/sample/rollback-payment.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

PLUGIN Parsian Bank Gateway For Woocommerce

CVE-2021-39309

MEDIUM CVSS 6.1 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-38361 - Htaccess Redirect Plugin

The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in the ~/htaccess-redirect.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.3.1.

PLUGIN Htaccess Redirect

CVE-2021-38361

MEDIUM CVSS 6.1 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-42549 - Lets Box Plugin

Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

PLUGIN Lets Box

CVE-2021-42549

MEDIUM CVSS 4.7 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-42548 - Share One Drive Plugin

Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

PLUGIN Share One Drive

CVE-2021-42548

MEDIUM CVSS 4.7 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-42547 - Out Of The Box Plugin

Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

PLUGIN Out Of The Box

CVE-2021-42547

MEDIUM CVSS 4.7 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24951 - Before 4 Plugin

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

PLUGIN Before 4

CVE-2021-24951

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24946 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

PLUGIN Modern Events Calendar Lite

CVE-2021-24946

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2026-01-16

CVE-2021-24863 - Nd Stop Bad Bots Crawlers And Spiders And Anti Spam Protection Plugin Stopbadbots

The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection

PLUGIN Nd Stop Bad Bots Crawlers And Spiders And Anti Spam Protection Plugin Stopbadbots

CVE-2021-24863

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24857 - Totop Link Plugin

The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

PLUGIN Totop Link

CVE-2021-24857

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24922 - Pixel Cat Plugin

The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks

PLUGIN Pixel Cat

CVE-2021-24922

CRITICAL CVSS 9.0 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24848 - Mediamaticajaxrenamecategory Ajax Action Of The Mediamatic Plugin

The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection

PLUGIN Mediamaticajaxrenamecategory Ajax Action Of The Mediamatic

CVE-2021-24848

HIGH CVSS 8.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24945 - Before 2 Plugin

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

PLUGIN Before 2

CVE-2021-24945

HIGH CVSS 8.0 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24970 - All In One Video Gallery Plugin

The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue

PLUGIN All In One Video Gallery

CVE-2021-24970

HIGH CVSS 7.2 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24861 - Quotes Collection Plugin

The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection

PLUGIN Quotes Collection

CVE-2021-24861

HIGH CVSS 7.2 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24872 - Get Custom Field Values Plugin

The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.

PLUGIN Get Custom Field Values

CVE-2021-24872

MEDIUM CVSS 6.5 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24955 - Before 3 Plugin

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24955

MEDIUM CVSS 6.1 2021-12-13
Scroll to top