Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16001-16020 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-24665 - Wp Video Lightbox Plugin

The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Wp Video Lightbox

CVE-2021-24665

MEDIUM CVSS 5.4 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24593 - Business Hours Indicator Plugin

The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue

PLUGIN Business Hours Indicator

CVE-2021-24593

MEDIUM CVSS 5.4 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24528 - Before 2 Plugin

The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles capable of managing plugins can modify the plugin's settings.

PLUGIN Before 2

CVE-2021-24528

MEDIUM CVSS 5.4 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24592 - Sitewide Notice Wp Plugin

The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Sitewide Notice Wp

CVE-2021-24592

MEDIUM CVSS 4.8 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24565 - Contact Form 7 Captcha Plugin

The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.

PLUGIN Contact Form 7 Captcha

CVE-2021-24565

HIGH CVSS 8.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24562 - Learning Management System Plugin

The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades

PLUGIN Learning Management System

CVE-2021-24562

HIGH CVSS 7.5 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24571 - Before 1 Plugin

The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-24571

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24564 - Wpfront Scroll Top Plugin

The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.

PLUGIN Wpfront Scroll Top

CVE-2021-24564

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-12-17

CVE-2021-24561 - Before 5 Plugin

The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue

PLUGIN Before 5

CVE-2021-24561

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24558 - Project Status Plugin

The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue

PLUGIN Project Status

CVE-2021-24558

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24658 - Before 3 Plugin

The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)

PLUGIN Before 3

CVE-2021-24658

MEDIUM CVSS 4.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24574 - Before 2 Plugin

The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24574

MEDIUM CVSS 4.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24551 - Edit Comments Plugin

The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue

PLUGIN Edit Comments

CVE-2021-24551

CRITICAL CVSS 9.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24506 - Before 8 Plugin

The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.

PLUGIN Before 8

CVE-2021-24506

HIGH CVSS 8.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24554 - Paytm Pay Plugin

The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue

PLUGIN Paytm Pay

CVE-2021-24554

HIGH CVSS 7.2 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24553 - Timeline Calendar Plugin

The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin

PLUGIN Timeline Calendar

CVE-2021-24553

HIGH CVSS 7.2 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24552 - Simple Events Calendar Plugin

The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue

PLUGIN Simple Events Calendar

CVE-2021-24552

HIGH CVSS 7.2 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24550 - Broken Link Manager Plugin

The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issue

PLUGIN Broken Link Manager

CVE-2021-24550

HIGH CVSS 7.2 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24497 - Giveaway Plugin

The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.

PLUGIN Giveaway

CVE-2021-24497

HIGH CVSS 7.2 2021-08-23
Scroll to top