Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15581-15600 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-42358 - Contact Form With Captcha Plugin

The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2.

PLUGIN Contact Form With Captcha

CVE-2021-42358

HIGH CVSS 8.8 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-42365 - Asgaros Forum Plugin

The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the name parameter found in the ~/admin/tables/admin-structure-table.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.13. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Asgaros Forum

CVE-2021-42365

MEDIUM CVSS 4.8 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24927 - My Calendar Plugin

The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN My Calendar

CVE-2021-24927

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24918 - Smash Balloon Social Post Feed Plugin

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

PLUGIN Smash Balloon Social Post Feed

CVE-2021-24918

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24915 - Contest Gallery Plugin

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

PLUGIN Contest Gallery

CVE-2021-24915

CRITICAL CVSS 9.8 2021-11-29
Threat Entry Updated 2025-10-17

CVE-2021-24755 - Before 2 Plugin

The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

PLUGIN Before 2

CVE-2021-24755

HIGH CVSS 8.8 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24748 - Email Before Download Plugin

The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues

PLUGIN Email Before Download

CVE-2021-24748

HIGH CVSS 8.8 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24860 - Bsk Pdf Manager Plugin

The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

PLUGIN Bsk Pdf Manager

CVE-2021-24860

HIGH CVSS 7.2 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24908 - Before 1 Plugin

The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-24908

MEDIUM CVSS 6.1 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24883 - Before 2 Plugin

The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2021-24883

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24842 - Bulk Datetime Change Plugin

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

PLUGIN Bulk Datetime Change

CVE-2021-24842

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24822 - Stylish Cost Calculator Plugin

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

PLUGIN Stylish Cost Calculator

CVE-2021-24822

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24751 - Before 1 Plugin

The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2021-24751

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24745 - About Author Box Plugin

The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.

PLUGIN About Author Box

CVE-2021-24745

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24899 - Media Tags Plugin

The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.

PLUGIN Media Tags

CVE-2021-24899

MEDIUM CVSS 4.8 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24811 - Shop Page Wp Plugin

The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Shop Page Wp

CVE-2021-24811

MEDIUM CVSS 4.8 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24768 - Wp Rss Aggregator Plugin

The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

PLUGIN Wp Rss Aggregator

CVE-2021-24768

MEDIUM CVSS 4.8 2021-11-29
Threat Entry Updated 2026-01-30

CVE-2021-24749 - Url Shortify Plugin

The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.

PLUGIN Url Shortify

CVE-2021-24749

MEDIUM CVSS 4.3 2021-11-29
Scroll to top