Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,426
Critical1,034
High3,419
Medium11,703
Reset
Showing 16221-16240 of 16426 records
Threat Entry Updated 2024-11-21

CVE-2021-24337 - Video Embed Box Plugin

The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.

PLUGIN Video Embed Box

CVE-2021-24337

HIGH CVSS 8.8 2021-06-07
Threat Entry Updated 2024-11-21

CVE-2021-24340 - Wp Statistics Plugin

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

PLUGIN Wp Statistics

CVE-2021-24340

HIGH CVSS 7.5 2021-06-07
Threat Entry Updated 2024-11-21

CVE-2021-24336 - Flightlog Plugin

The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users

PLUGIN Flightlog

CVE-2021-24336

HIGH CVSS 7.2 2021-06-07
Threat Entry Updated 2024-11-21

CVE-2021-24342 - Jnews Plugin

The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

PLUGIN Jnews

CVE-2021-24342

MEDIUM CVSS 6.1 2021-06-07
Threat Entry Updated 2024-11-21

CVE-2021-24343 - Before 4 Plugin

The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 4

CVE-2021-24343

MEDIUM CVSS 4.8 2021-06-07
Threat Entry Updated 2024-11-21

CVE-2021-24321 - Bello Plugin

The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues

PLUGIN Bello

CVE-2021-24321

CRITICAL CVSS 9.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24333 - Content Copy Protection Prevent Image Save Plugin

The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in administrator set arbitrary XSS payloads in them.

PLUGIN Content Copy Protection Prevent Image Save

CVE-2021-24333

MEDIUM CVSS 6.5 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24318 - Listeo Plugin

The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.

PLUGIN Listeo

CVE-2021-24318

MEDIUM CVSS 6.5 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24328 - Wp Login Security And History Plugin

The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well

PLUGIN Wp Login Security And History

CVE-2021-24328

MEDIUM CVSS 6.2 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24335 - Car Repair Services Auto Mechanic Plugin

The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

PLUGIN Car Repair Services Auto Mechanic

CVE-2021-24335

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24320 - Bello Plugin

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.

PLUGIN Bello

CVE-2021-24320

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24334 - One Click Unsplash Uploads Plugin

The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Scripting issue.

PLUGIN One Click Unsplash Uploads

CVE-2021-24334

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24329 - Wp Super Cache Plugin

The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.

PLUGIN Wp Super Cache

CVE-2021-24329

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24322 - Database Backup For Plugin

The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.

PLUGIN Database Backup For

CVE-2021-24322

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24319 - Bello Plugin

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue

PLUGIN Bello

CVE-2021-24319

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24331 - Down Buttons Plugin

The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them

PLUGIN Down Buttons

CVE-2021-24331

MEDIUM CVSS 4.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24330 - Create High Converting Sales Funnels For Plugin

The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole website depending on the settings used.

PLUGIN Create High Converting Sales Funnels For

CVE-2021-24330

MEDIUM CVSS 4.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24312 - Pages Used In The Settings Of Wp Super Cache Plugin

The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.

PLUGIN Pages Used In The Settings Of Wp Super Cache

CVE-2021-24312

HIGH CVSS 7.2 2021-06-01
Scroll to top