Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16041-16060 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-34655 - Wp Songbook Plugin

The WP Songbook WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the url parameter found in the ~/inc/class.ajax.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.11.

PLUGIN Wp Songbook

CVE-2021-34655

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34641 - Seopress Plugin

The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.

PLUGIN Seopress

CVE-2021-34641

MEDIUM CVSS 6.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34654 - Custom Post Type Relations Plugin

The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] parameter found in the ~/pages/admin-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

PLUGIN Custom Post Type Relations

CVE-2021-34654

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34653 - Wp Fountain Plugin

The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/wp-fountain.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.9.

PLUGIN Wp Fountain

CVE-2021-34653

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34652 - Media Usage Plugin

The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.4.

PLUGIN Media Usage

CVE-2021-34652

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34651 - Scribble Maps Plugin

The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includes/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

PLUGIN Scribble Maps

CVE-2021-34651

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34649 - Simple Behace Portfolio Plugin

The Simple Behance Portfolio WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `dark` parameter in the ~/titan-framework/iframe-font-preview.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.2.

PLUGIN Simple Behace Portfolio

CVE-2021-34649

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34644 - Multiplayer Games Plugin

The Multiplayer Games WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/multiplayergames.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.7.

PLUGIN Multiplayer Games

CVE-2021-34644

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34643 - Skaut Bazar Plugin

The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/skaut-bazar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.2.

PLUGIN Skaut Bazar

CVE-2021-34643

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34642 - Smart Email Alerts Plugin

The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.10.

PLUGIN Smart Email Alerts

CVE-2021-34642

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24536 - Custom Login Redirect Plugin

The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored Cross-Site Scripting issue

PLUGIN Custom Login Redirect

CVE-2021-24536

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24548 - Mimetic Books Plugin

The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page.

PLUGIN Mimetic Books

CVE-2021-24548

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24541 - Wonder Pdf Embed Plugin

The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.

PLUGIN Wonder Pdf Embed

CVE-2021-24541

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24540 - Wonder Video Embed Plugin

The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.

PLUGIN Wonder Video Embed

CVE-2021-24540

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24538 - Current Book Plugin

The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.

PLUGIN Current Book

CVE-2021-24538

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24527 - Profile Builder Plugin

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.

PLUGIN Profile Builder

CVE-2021-24527

CRITICAL CVSS 9.8 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24535 - Light Messages Plugin

The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting payload in the Message Content. Depending on the options set, the XSS payload can be triggered either in the backend only (in the plugin's settings), or both frontend and backend.

PLUGIN Light Messages

CVE-2021-24535

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24466 - Verse O Matic Plugin

The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues

PLUGIN Verse O Matic

CVE-2021-24466

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24411 - Social Tape Plugin

The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attack

PLUGIN Social Tape

CVE-2021-24411

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24410 - Telugu Bible Verse Daily Plugin

The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses containing JavaScript code in them, leading to Stored XSS issues

PLUGIN Telugu Bible Verse Daily

CVE-2021-24410

MEDIUM CVSS 6.1 2021-08-16
Scroll to top