Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 15981-16000 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-24591 - Before 0 Plugin

The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 0

CVE-2021-24591

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24590 - Ccpa Compliance Plugin

The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options.

PLUGIN Ccpa Compliance

CVE-2021-24590

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24568 - Addtoany Share Buttons Plugin

The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Addtoany Share Buttons

CVE-2021-24568

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24517 - Before 2021 Plugin

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed

PLUGIN Before 2021

CVE-2021-24517

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24513 - Create Responsive Contact Forms Plugin

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

PLUGIN Create Responsive Contact Forms

CVE-2021-24513

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24391 - Cashtomer Plugin

An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Cashtomer

CVE-2021-24391

HIGH CVSS 8.8 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24393 - Comment Highlighter Plugin

A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Comment Highlighter

CVE-2021-24393

HIGH CVSS 7.2 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24392 - Club Management Software Plugin

An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Club Management Software

CVE-2021-24392

HIGH CVSS 7.2 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24390 - Alipay Plugin

A proid GET parameter of the WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.

PLUGIN Alipay

CVE-2021-24390

HIGH CVSS 7.2 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-34646 - Booster For Woocommerce Plugin

Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file. This allows attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Email Verification module to be active in the plugin and the Login User After Successful Verification setting to be…

PLUGIN Booster For Woocommerce

CVE-2021-34646

CRITICAL CVSS 9.8 2021-08-30
Threat Entry Updated 2026-02-04

CVE-2021-34668 - Wordpress Real Media Library Plugin

The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in the ~/inc/overrides/lite/rest/Folder.php file which allows author-level attackers to inject arbitrary web scripts in folder names, in versions up to and including 4.14.1.

PLUGIN Wordpress Real Media Library

CVE-2021-34668

MEDIUM CVSS 6.4 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24581 - Blue Admin Plugin

The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

PLUGIN Blue Admin

CVE-2021-24581

HIGH CVSS 8.8 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24580 - Side Menu Lite Plugin

The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue

PLUGIN Side Menu Lite

CVE-2021-24580

HIGH CVSS 8.8 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24579 - Grid Ajax Action Of The Bold Page Builder Plugin

The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases.

PLUGIN Grid Ajax Action Of The Bold Page Builder

CVE-2021-24579

HIGH CVSS 8.8 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24438 - Sharethis Dashboard For Google Analytics Plugin

The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

PLUGIN Sharethis Dashboard For Google Analytics

CVE-2021-24438

MEDIUM CVSS 6.1 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24437 - Favicon By Realfavicongenerator Plugin

The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

PLUGIN Favicon By Realfavicongenerator

CVE-2021-24437

MEDIUM CVSS 6.1 2021-08-30
Scroll to top