Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 15941-15960 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-38351 - Osd Subscribe Plugin

The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.3.

PLUGIN Osd Subscribe

CVE-2021-38351

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38350 - Spideranalyse Plugin

The spideranalyse WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the date parameter found in the ~/analyse/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.1.

PLUGIN Spideranalyse

CVE-2021-38350

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38349 - Woo Moneybird Plugin

The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1.

PLUGIN Woo Moneybird

CVE-2021-38349

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38348 - Advance Search Plugin

The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in the ~/inc/admin/views/html-advance-search-admin-options.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.2.

PLUGIN Advance Search

CVE-2021-38348

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38347 - Simple Custom Website Data Plugin

The Custom Website Data WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter found in the ~/views/edit.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.2.

PLUGIN Simple Custom Website Data

CVE-2021-38347

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38341 - Wc Payment Gateway Per Category Plugin

The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.10.

PLUGIN Wc Payment Gateway Per Category

CVE-2021-38341

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38340 - Webful Simple Grocery Shop Plugin

The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

PLUGIN Webful Simple Grocery Shop

CVE-2021-38340

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38339 - Simple Matted Thumbnails Plugin

The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simple-matted-thumbnail.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.01.

PLUGIN Simple Matted Thumbnails

CVE-2021-38339

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38338 - Border Loading Bar Plugin

The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter found in the ~/titan-framework/iframe-googlefont-preview.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

PLUGIN Border Loading Bar

CVE-2021-38338

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38337 - Rsvpmaker Excel Plugin

The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.

PLUGIN Rsvpmaker Excel

CVE-2021-38337

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38336 - Edit Comments Xt Plugin

The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

PLUGIN Edit Comments Xt

CVE-2021-38336

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38335 - Wise Agent Capture Forms Plugin

The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/WiseAgentCaptureForm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

PLUGIN Wise Agent Capture Forms

CVE-2021-38335

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38334 - Wp Design Maps Places Plugin

The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter found in the ~/wpdmp-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

PLUGIN Wp Design Maps Places

CVE-2021-38334

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38333 - Wp Scrippets Plugin

The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.1.

PLUGIN Wp Scrippets

CVE-2021-38333

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38332 - Ops Robots Txt Plugin

The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

PLUGIN Ops Robots Txt

CVE-2021-38332

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38331 - Wp T Wap Plugin

The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.13.2.

PLUGIN Wp T Wap

CVE-2021-38331

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38330 - Yabp Plugin

The Yet Another bol.com Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/yabp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.

PLUGIN Yabp

CVE-2021-38330

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38329 - Dj Email Publish Plugin

The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/dj-email-publish.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.7.2.

PLUGIN Dj Email Publish

CVE-2021-38329

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38328 - Notices Plugin

The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1.

PLUGIN Notices

CVE-2021-38328

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38327 - Youtube Video Inserter Plugin

The YouTube Video Inserter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/adminUI/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.1.0.

PLUGIN Youtube Video Inserter

CVE-2021-38327

MEDIUM CVSS 6.1 2021-09-10
Scroll to top