Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16081-16100 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-24467 - Leaflet Map Plugin

The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being used, or using malicious attributions which will be executed in all page with an embed map from the plugin

PLUGIN Leaflet Map

CVE-2021-24467

MEDIUM CVSS 6.5 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24495 - Marmoset Viewer Plugin

The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.

PLUGIN Marmoset Viewer

CVE-2021-24495

MEDIUM CVSS 6.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24304 - Newsmag Plugin

The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

PLUGIN Newsmag

CVE-2021-24304

MEDIUM CVSS 6.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24509 - Page View Count Plugin

The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

PLUGIN Page View Count

CVE-2021-24509

MEDIUM CVSS 5.4 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24505 - Before 1 Plugin

The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the Forms "Add new" field.

PLUGIN Before 1

CVE-2021-24505

MEDIUM CVSS 5.4 2021-08-09
Threat Entry Updated 2025-05-07

CVE-2021-24502 - Wp Google Map Plugin

The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed

PLUGIN Wp Google Map

CVE-2021-24502

MEDIUM CVSS 4.8 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-34634 - Sola Newsletters Plugin

The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.

PLUGIN Sola Newsletters

CVE-2021-34634

HIGH CVSS 8.8 2021-08-05
Threat Entry Updated 2024-11-21

CVE-2021-34633 - Youtube Feeder Plugin

The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.1.

PLUGIN Youtube Feeder

CVE-2021-34633

HIGH CVSS 8.8 2021-08-05
Threat Entry Updated 2024-11-21

CVE-2021-34631 - Newsplugin

The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in the ~/news-plugin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.18.

PLUGIN Newsplugin

CVE-2021-34631

HIGH CVSS 8.8 2021-08-05
Threat Entry Updated 2024-11-21

CVE-2021-34637 - Post Index Plugin

The Post Index WordPress plugin is vulnerable to Cross-Site Request Forgery via the OptionsPage function found in the ~/php/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.5.

PLUGIN Post Index

CVE-2021-34637

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-34632 - Seo Backlinks Plugin

The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.1.

PLUGIN Seo Backlinks

CVE-2021-34632

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-34628 - Admin Custom Login Plugin

The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.7.

PLUGIN Admin Custom Login

CVE-2021-34628

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-34635 - Poll Maker Plugin

The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.8.

PLUGIN Poll Maker

CVE-2021-34635

MEDIUM CVSS 6.1 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24504 - Wp Learn Manager Plugin

The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)

PLUGIN Wp Learn Manager

CVE-2021-24504

MEDIUM CVSS 6.1 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24498 - Calendar Event Multi View Plugin

The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.

PLUGIN Calendar Event Multi View

CVE-2021-24498

MEDIUM CVSS 6.1 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24503 - Simple Icons Plugin

The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

PLUGIN Simple Icons

CVE-2021-24503

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24472 - 2 And Qt Kentharadio Plugin

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

PLUGIN 2 And Qt Kentharadio

CVE-2021-24472

CRITICAL CVSS 9.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24492 - Before 2 Plugin

The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.

PLUGIN Before 2

CVE-2021-24492

HIGH CVSS 8.8 2021-08-02
Scroll to top