Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16021-16040 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-24556 - Email Subscriber Plugin

The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sanitise, validate and escape the submitted subscribe_email and subscribe_name POST parameters, inserting them in the DB and then outputting them back in the Subscriber list (/wp-admin/edit.php?post_type=kes_campaign&page=kento_email_subscriber_list_settings), leading a Stored XSS issue.

PLUGIN Email Subscriber

CVE-2021-24556

MEDIUM CVSS 6.1 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24531 - Before 1 Plugin

The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.

PLUGIN Before 1

CVE-2021-24531

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24529 - Photo Image Grid Gallery Plugin

The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.

PLUGIN Photo Image Grid Gallery

CVE-2021-24529

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24486 - Social Sharing For Everyone Plugin

The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Social Sharing For Everyone

CVE-2021-24486

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24549 - Aceide Plugin

The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths before using it in various actions, such as to read arbitrary files from the server. This allows high privilege users such as administrator to access any file on the web server outside of the blog directory via a path traversal attack.

PLUGIN Aceide

CVE-2021-24549

MEDIUM CVSS 4.9 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24533 - Before 4 Plugin

The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend

PLUGIN Before 4

CVE-2021-24533

MEDIUM CVSS 4.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24524 - Donation Plugin And Fundraising Platform

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.

PLUGIN Donation Plugin And Fundraising Platform

CVE-2021-24524

MEDIUM CVSS 4.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-34645 - Wp Easycart Plugin

The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0.

PLUGIN Wp Easycart

CVE-2021-34645

HIGH CVSS 8.8 2021-08-19
Threat Entry Updated 2024-11-21

CVE-2021-38315 - Sp Client Document Manager Plugin

The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in the ~/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.25.

PLUGIN Sp Client Document Manager

CVE-2021-38315

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34667 - Calendar Plugin

The Calendar_plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of `$_SERVER['PHP_SELF']` in the ~/calendar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

PLUGIN Calendar

CVE-2021-34667

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34666 - Sidebar Adder Plugin

The Add Sidebar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the add parameter in the ~/wp_sidebarMenu.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.0.

PLUGIN Sidebar Adder

CVE-2021-34666

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34665 - Wp Seo Tags Plugin

The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in the ~/wp-seo-tags.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.2.7.

PLUGIN Wp Seo Tags

CVE-2021-34665

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34664 - Moova For Woocommerce Plugin

The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the ~/Checkout/Checkout.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.

PLUGIN Moova For Woocommerce

CVE-2021-34664

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34663 - Jquery Tagline Rotator Plugin

The jQuery Tagline Rotator WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/jquery-tagline-rotator.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.1.5.

PLUGIN Jquery Tagline Rotator

CVE-2021-34663

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34659 - Plugmatter Pricing Table Plugin

The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` parameter in the ~/license.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.32.

PLUGIN Plugmatter Pricing Table

CVE-2021-34659

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34658 - Simple Popup Newsletter Plugin

The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/simple-popup-newsletter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.7.

PLUGIN Simple Popup Newsletter

CVE-2021-34658

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34657 - Typofr Plugin

The 2TypoFR WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the text function found in the ~/vendor/Org_Heigl/Hyphenator/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.11.

PLUGIN Typofr

CVE-2021-34657

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34656 - Webcam 2way Videochat Plugin

The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.2.7.

PLUGIN Webcam 2way Videochat

CVE-2021-34656

MEDIUM CVSS 6.1 2021-08-16
Scroll to top