Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,429
Critical1,034
High3,419
Medium11,703
Reset
Showing 16421-16429 of 16429 records
Threat Entry Updated 2024-11-21

CVE-2021-24134 - Unvalidated Input And Lack Of Output Encoding In The Constant Contact Forms Plugin

Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.

PLUGIN Unvalidated Input And Lack Of Output Encoding In The Constant Contact Forms

CVE-2021-24134

MEDIUM CVSS 4.8 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24123 - Arbitrary File Upload In The Powerpress Plugin

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

PLUGIN Arbitrary File Upload In The Powerpress

CVE-2021-24123

HIGH CVSS 7.2 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24124 - Wp Shieldon Plugin

Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is shown could lead to privileged escalation.

PLUGIN Wp Shieldon

CVE-2021-24124

MEDIUM CVSS 6.1 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24127 - Input And Lack Of Output Encoding In The Thirstyaffiliates Affiliate Link Manager Plugin

Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.

PLUGIN Input And Lack Of Output Encoding In The Thirstyaffiliates Affiliate Link Manager

CVE-2021-24127

MEDIUM CVSS 5.4 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24126 - Unvalidated Input And Lack Of Output Encoding In The Envira Gallery Lite Plugin

Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.

PLUGIN Unvalidated Input And Lack Of Output Encoding In The Envira Gallery Lite

CVE-2021-24126

MEDIUM CVSS 5.4 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-3120 - Yith Woocommerce Gift Cards Plugin

An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a valid Gift Card product into the shopping cart. An uploaded file is placed at a predetermined path on the web server with a user-specified filename and extension. This occurs because the ywgc-upload-picture parameter can have a .php value even…

PLUGIN Yith Woocommerce Gift Cards

CVE-2021-3120

CRITICAL CVSS 9.8 2021-02-22
Scroll to top