Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16141-16160 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-24482 - Related Posts Plugin

The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues.

PLUGIN Related Posts

CVE-2021-24482

MEDIUM CVSS 4.8 2021-07-19
Threat Entry Updated 2024-11-21

CVE-2021-20781 - Wordpress Meta Data And Taxonomies Filter Plugin

Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.2.8 and versions prior to v.2.2.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

PLUGIN Wordpress Meta Data And Taxonomies Filter

CVE-2021-20781

HIGH CVSS 8.8 2021-07-14
Threat Entry Updated 2024-11-21

CVE-2021-24442 - Questionnaire And Voting System Plugin

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

PLUGIN Questionnaire And Voting System

CVE-2021-24442

CRITICAL CVSS 9.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24441 - Sign Up Sheets Plugin

The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue

PLUGIN Sign Up Sheets

CVE-2021-24441

HIGH CVSS 8.0 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24454 - In The Yop Poll Plugin

In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS payload depends on the 'Show results' option selected, which could be before or after sending the vote for example.

PLUGIN In The Yop Poll

CVE-2021-24454

MEDIUM CVSS 6.1 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24434 - Glass Plugin

The Glass WordPress plugin through 1.3.2 does not sanitise or escape its "Glass Pages" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin did not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

PLUGIN Glass

CVE-2021-24434

MEDIUM CVSS 6.1 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24429 - Salon Booking System Plugin

The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" page and the malicious script is executed in the admin context.

PLUGIN Salon Booking System

CVE-2021-24429

MEDIUM CVSS 6.1 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24439 - Browser Screenshots Plugin

The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped.

PLUGIN Browser Screenshots

CVE-2021-24439

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24424 - Most Advanced Wordpress Reset Tool Plugin

The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Most Advanced Wordpress Reset Tool

CVE-2021-24424

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24421 - Wp Jobsearch Plugin

The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue

PLUGIN Wp Jobsearch

CVE-2021-24421

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24420 - Request A Quote Plugin

The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.

PLUGIN Request A Quote

CVE-2021-24420

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24440 - Sign Up Sheets Plugin

The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard

PLUGIN Sign Up Sheets

CVE-2021-24440

MEDIUM CVSS 4.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24427 - W3 Total Cache Plugin

The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN W3 Total Cache

CVE-2021-24427

MEDIUM CVSS 4.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24426 - Backup Wd Plugin

The Backup by 10Web – Backup and Restore Plugin WordPress plugin through 1.0.20 does not sanitise or escape the tab parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

PLUGIN Backup Wd

CVE-2021-24426

MEDIUM CVSS 4.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24409 - Before 2 Plugin

The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

PLUGIN Before 2

CVE-2021-24409

MEDIUM CVSS 6.1 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24408 - Before 2 Plugin

The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

PLUGIN Before 2

CVE-2021-24408

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24365 - Free Plugin

The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.

PLUGIN Free

CVE-2021-24365

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24419 - Wp Youtube Lyte Plugin

The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification settings before outputting them back in the page, allowing high privilege users to set XSS payload on them and leading to stored Cross-Site Scripting issues.

PLUGIN Wp Youtube Lyte

CVE-2021-24419

MEDIUM CVSS 4.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24418 - Smooth Scroll Page Up Down Buttons Plugin

The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_positioning settings, allowing high privilege users such as admin to set an XSS payload in it, which will be executed in all pages of the blog

PLUGIN Smooth Scroll Page Up Down Buttons

CVE-2021-24418

MEDIUM CVSS 4.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-34624 - Profilepress Plugin

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

PLUGIN Profilepress

CVE-2021-34624

CRITICAL CVSS 9.8 2021-07-07
Scroll to top