Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,422
Critical1,033
High3,417
Medium11,702
Reset
Showing 15921-15940 of 16422 records
Threat Entry Updated 2024-11-21

CVE-2021-24614 - Book Appointment Online Plugin

The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Book Appointment Online

CVE-2021-24614

MEDIUM CVSS 4.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24560 - Software License Manager Plugin

The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Software License Manager

CVE-2021-24560

MEDIUM CVSS 6.1 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24605 - Custom Post View Generator Plugin

The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue

PLUGIN Custom Post View Generator

CVE-2021-24605

MEDIUM CVSS 5.4 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24523 - Daily Prayer Time Plugin

The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputting them in the page, leading to Authenticated Stored Cross-Site Scripting issues.

PLUGIN Daily Prayer Time

CVE-2021-24523

MEDIUM CVSS 5.4 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24586 - Per Page Add To Head Plugin

The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned by the plugin), this could lead to Stored XSS issue which will be triggered either in the backend, frontend or both depending on the payload used.

PLUGIN Per Page Add To Head

CVE-2021-24586

MEDIUM CVSS 4.3 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24493 - Shopp Plugin

The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have any security measure in place to prevent upload of malicious files, such as PHP, allowing unauthenticated users to upload arbitrary files and leading to RCE

PLUGIN Shopp

CVE-2021-24493

CRITICAL CVSS 9.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24510 - Mf Gig Calendar Plugin

The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

PLUGIN Mf Gig Calendar

CVE-2021-24510

MEDIUM CVSS 6.1 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24508 - Smash Balloon Social Post Feed Plugin

The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.

PLUGIN Smash Balloon Social Post Feed

CVE-2021-24508

MEDIUM CVSS 6.1 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24491 - Fileviewer Plugin

The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload and delete files. As a result, attackers could make a logged in administrator delete and upload arbitrary files via a CSRF attack

PLUGIN Fileviewer

CVE-2021-24491

HIGH CVSS 8.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24490 - Email Artillery Plugin

The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the presence of a .htaccess, denying access to everything in the folder the file is uploaded to, the malicious uploaded file will only be accessible on Web Servers such as Nginx/IIS

PLUGIN Email Artillery

CVE-2021-24490

MEDIUM CVSS 6.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24431 - Language Bar Flags Plugin

The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users

PLUGIN Language Bar Flags

CVE-2021-24431

MEDIUM CVSS 4.3 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-38360 - Wp Publications Plugin

The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to and including 0.0.

PLUGIN Wp Publications

CVE-2021-38360

HIGH CVSS 8.3 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38359 - Refer A Friend Widget For Wp Plugin

The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.1.

PLUGIN Refer A Friend Widget For Wp

CVE-2021-38359

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38358 - Moolamojo Plugin

The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.4.1.

PLUGIN Moolamojo

CVE-2021-38358

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38357 - Sms Ovh Plugin

The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/sms-ovh-sent.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.1.

PLUGIN Sms Ovh

CVE-2021-38357

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38355 - Bug Library Plugin

The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.3.

PLUGIN Bug Library

CVE-2021-38355

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38354 - Gnu Mailman Integration Plugin

The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.

PLUGIN Gnu Mailman Integration

CVE-2021-38354

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38353 - Dropdown And Scrollable Text Plugin

The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.

PLUGIN Dropdown And Scrollable Text

CVE-2021-38353

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38352 - Push Notification By Feedify Plugin

The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.

PLUGIN Push Notification By Feedify

CVE-2021-38352

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38351 - Osd Subscribe Plugin

The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.3.

PLUGIN Osd Subscribe

CVE-2021-38351

MEDIUM CVSS 6.1 2021-09-10
Scroll to top