Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16101-16120 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-24484 - Function In The Secure Copy Content Protection And Content Locking Plugin

The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Function In The Secure Copy Content Protection And Content Locking

CVE-2021-24484

HIGH CVSS 7.2 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24483 - Functions In The Poll Maker Plugin

The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Functions In The Poll Maker

CVE-2021-24483

HIGH CVSS 7.2 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24496 - Community Events Plugin

The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

PLUGIN Community Events

CVE-2021-24496

MEDIUM CVSS 6.1 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24477 - Migrate Users Plugin

The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its options, allowing the issue to be exploited via a CSRF attack.

PLUGIN Migrate Users

CVE-2021-24477

MEDIUM CVSS 6.1 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24474 - Awesome Weather Widget Plugin

The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.

PLUGIN Awesome Weather Widget

CVE-2021-24474

MEDIUM CVSS 6.1 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24478 - Bookshelf Plugin

The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Bookshelf

CVE-2021-24478

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24476 - Steam Group Viewer Plugin

The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Steam Group Viewer

CVE-2021-24476

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24473 - User Profile Picture Plugin

The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).

PLUGIN User Profile Picture

CVE-2021-24473

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24470 - Before 3 Plugin

The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24470

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24481 - Any Hostname Plugin

The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an authenticated stored XSS issue as high privilege users are able to set XSS payloads in it

PLUGIN Any Hostname

CVE-2021-24481

MEDIUM CVSS 4.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24480 - Event Geek Plugin

The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting it in the page, leading to an authenticated (admin+) stored Cross-Site Scripting issue

PLUGIN Event Geek

CVE-2021-24480

MEDIUM CVSS 4.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24479 - Drawblog Plugin

The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue

PLUGIN Drawblog

CVE-2021-24479

MEDIUM CVSS 4.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24463 - Function In The Image Slider By Ays Responsive Slider And Carousel Plugin

The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Function In The Image Slider By Ays Responsive Slider And Carousel

CVE-2021-24463

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24462 - Responsive Image Gallery Plugin

The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Responsive Image Gallery

CVE-2021-24462

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24461 - Function In The Faq Builder Ays Plugin

The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Function In The Faq Builder Ays

CVE-2021-24461

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24460 - Before 3 Plugin

The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Before 3

CVE-2021-24460

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24459 - Functions In The Survey Maker Plugin

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Functions In The Survey Maker

CVE-2021-24459

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24458 - Functions Of The Popup Box Plugin

The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Functions Of The Popup Box

CVE-2021-24458

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24457 - Php Files Of The Portfolio Responsive Gallery Plugin

The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Gallery WordPress plugin before 1.1.8 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Php Files Of The Portfolio Responsive Gallery

CVE-2021-24457

HIGH CVSS 8.8 2021-08-02
Scroll to top