Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,429
Critical1,034
High3,419
Medium11,703
Reset
Showing 16401-16420 of 16429 records
Threat Entry Updated 2024-11-21

CVE-2021-24153 - A Stored Cross Site Scripting Vulnerability Was Discovered In The Yoast Seo Plugin

A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.

PLUGIN A Stored Cross Site Scripting Vulnerability Was Discovered In The Yoast Seo

CVE-2021-24153

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24154 - Theme Editor Plugin

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

PLUGIN Theme Editor

CVE-2021-24154

MEDIUM CVSS 4.9 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-21389 - To Build A Community Site Plugin

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

PLUGIN To Build A Community Site

CVE-2021-21389

HIGH CVSS 8.1 2021-03-26
Threat Entry Updated 2024-11-21

CVE-2021-24149 - Unvalidated Input In The Modern Events Calendar Lite Plugin

Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

PLUGIN Unvalidated Input In The Modern Events Calendar Lite

CVE-2021-24149

HIGH CVSS 8.8 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24146 - Lack Of Authorisation Checks In The Modern Events Calendar Lite Plugin

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

PLUGIN Lack Of Authorisation Checks In The Modern Events Calendar Lite

CVE-2021-24146

HIGH CVSS 7.5 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24145 - Arbitrary File Upload In The Modern Events Calendar Lite Plugin

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

PLUGIN Arbitrary File Upload In The Modern Events Calendar Lite

CVE-2021-24145

HIGH CVSS 7.2 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24147 - Unvalidated Input And Lack Of Output Encoding In The Modern Events Calendar Lite Plugin

Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_comment field (Notes on time) when adding/editing an event, allowing users with privilege as low as author to add events with a Cross-Site Scripting payload in them, which will be triggered in the frontend when viewing the event.

PLUGIN Unvalidated Input And Lack Of Output Encoding In The Modern Events Calendar Lite

CVE-2021-24147

MEDIUM CVSS 5.4 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24139 - Photo Gallery Plugin

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

PLUGIN Photo Gallery

CVE-2021-24139

CRITICAL CVSS 9.8 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24132 - Slider By 10web Plugin

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.

PLUGIN Slider By 10web

CVE-2021-24132

HIGH CVSS 8.8 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24135 - Unvalidated Input And Lack Of Output Encoding In The Wp Customer Reviews Plugin

Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.

PLUGIN Unvalidated Input And Lack Of Output Encoding In The Wp Customer Reviews

CVE-2021-24135

MEDIUM CVSS 6.1 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24136 - Unvalidated Input And Lack Of Output Encoding In The Testimonials Widget Plugin

Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL

PLUGIN Unvalidated Input And Lack Of Output Encoding In The Testimonials Widget

CVE-2021-24136

MEDIUM CVSS 5.4 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24129 - Unvalidated Input And Lack Of Output Encoding In The Themify Portfolio Post Plugin

Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged users (Contributor+) to inject arbitrary JavaScript code or HTML in posts where the Themify Custom Panel is embedded, which could lead to privilege escalation.

PLUGIN Unvalidated Input And Lack Of Output Encoding In The Themify Portfolio Post

CVE-2021-24129

MEDIUM CVSS 5.4 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24128 - Unvalidated Input And Lack Of Output Encoding In The Team Members Plugin

Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.

PLUGIN Unvalidated Input And Lack Of Output Encoding In The Team Members

CVE-2021-24128

MEDIUM CVSS 5.4 2021-03-18
Scroll to top