Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 15961-15980 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-38326 - Post Title Counter Plugin

The Post Title Counter WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the notice parameter found in the ~/post-title-counter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.

PLUGIN Post Title Counter

CVE-2021-38326

MEDIUM CVSS 6.1 2021-09-10
Threat Entry Updated 2024-11-21

CVE-2021-38324 - Sp Rental Manager Plugin

The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.

PLUGIN Sp Rental Manager

CVE-2021-38324

HIGH CVSS 8.2 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38325 - User Activation Email Plugin

The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter found in the ~/user-activation-email.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.0.

PLUGIN User Activation Email

CVE-2021-38325

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38323 - Rentpress Plugin

The RentPress WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selections parameter found in the ~/src/rentPress/AjaxRequests.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.6.4.

PLUGIN Rentpress

CVE-2021-38323

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38322 - Twitter Friends Widget Plugin

The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.1.

PLUGIN Twitter Friends Widget

CVE-2021-38322

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38321 - Custom Sub Menus Plugin

The Custom Menu Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selected_menu parameter found in the ~/custom-menus.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.3.

PLUGIN Custom Sub Menus

CVE-2021-38321

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38320 - Simplesamlphp Authentication Plugin

The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0.

PLUGIN Simplesamlphp Authentication

CVE-2021-38320

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38319 - More From Google Plugin

The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/morefromgoogle.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.2.

PLUGIN More From Google

CVE-2021-38319

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38318 - 3d Cover Carousel Plugin

The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cover-carousel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

PLUGIN 3d Cover Carousel

CVE-2021-38318

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38317 - Konnichiwa Plugin

The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in the ~/views/subscriptions.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.8.3.

PLUGIN Konnichiwa

CVE-2021-38317

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-38316 - Wp Academic People Plugin

The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name parameter in the ~/admin-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.4.1.

PLUGIN Wp Academic People

CVE-2021-38316

MEDIUM CVSS 6.1 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-36871 - Wp Go Maps Plugin

Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.

PLUGIN Wp Go Maps

CVE-2021-36871

MEDIUM CVSS 5.5 2021-09-09
Threat Entry Updated 2024-11-21

CVE-2021-24395 - Embed Youtube Video Plugin

The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Embed Youtube Video

CVE-2021-24395

HIGH CVSS 7.2 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24599 - Protect Email Addresses Plugin

The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.

PLUGIN Protect Email Addresses

CVE-2021-24599

MEDIUM CVSS 6.1 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24611 - Keyword Meta Plugin

The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.

PLUGIN Keyword Meta

CVE-2021-24611

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24603 - Site Reviews Plugin

The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed

PLUGIN Site Reviews

CVE-2021-24603

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24601 - Wpfront Notification Bar Plugin

The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Wpfront Notification Bar

CVE-2021-24601

MEDIUM CVSS 5.4 2021-09-06
Scroll to top