Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15781-15800 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-39344 - Kjm Admin Notices Plugin

The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/class-kjm-admin-notices-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Kjm Admin Notices

CVE-2021-39344

MEDIUM CVSS 5.5 2021-10-15
Threat Entry Updated 2024-11-21

CVE-2021-39338 - Mybb Cross Poster Plugin

The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Mybb Cross Poster

CVE-2021-39338

MEDIUM CVSS 5.5 2021-10-15
Threat Entry Updated 2024-11-21

CVE-2021-39337 - Job Portal Plugin

The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/jobs_function.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Job Portal

CVE-2021-39337

MEDIUM CVSS 5.5 2021-10-15
Threat Entry Updated 2024-11-21

CVE-2021-39336 - Job Manager Plugin

The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.7.25. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Job Manager

CVE-2021-39336

MEDIUM CVSS 5.5 2021-10-15
Threat Entry Updated 2024-11-21

CVE-2021-39335 - Wpgenious Job Listing Plugin

The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/admin/class/class-wpgenious-job-listing-options.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Wpgenious Job Listing

CVE-2021-39335

MEDIUM CVSS 5.5 2021-10-15
Threat Entry Updated 2024-11-21

CVE-2021-39334 - Job Board Vanilla Plugin

The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the psjb_exp_in and the psjb_curr_in parameters found in the ~/job-settings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Job Board Vanilla

CVE-2021-39334

MEDIUM CVSS 5.5 2021-10-15
Threat Entry Updated 2026-01-20

CVE-2021-39332 - Business Manager Plugin

The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization found throughout the plugin which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.4.5. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Business Manager

CVE-2021-39332

MEDIUM CVSS 5.5 2021-10-15
Threat Entry Updated 2024-11-21

CVE-2021-39317 - Access Demo Importer Plugin

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer

PLUGIN Access Demo Importer

CVE-2021-39317

HIGH CVSS 8.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24719 - Enfold Plugin

The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.

PLUGIN Enfold

CVE-2021-24719

MEDIUM CVSS 6.1 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24683 - Weather Effect Plugin

The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.

PLUGIN Weather Effect

CVE-2021-24683

MEDIUM CVSS 5.4 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24737 - Wpdiscuz Plugin

The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Wpdiscuz

CVE-2021-24737

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24709 - Weather Effect Plugin

The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues

PLUGIN Weather Effect

CVE-2021-24709

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24691 - Quiz And Survey Master Plugin

The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Quiz And Survey Master

CVE-2021-24691

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24681 - Duplicate Page Plugin

The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Duplicate Page

CVE-2021-24681

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24546 - Before 1 Plugin

The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code

PLUGIN Before 1

CVE-2021-24546

HIGH CVSS 8.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24651 - Before 3 Plugin

The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.

PLUGIN Before 3

CVE-2021-24651

HIGH CVSS 7.5 2021-10-11
Scroll to top