Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Xwiki HIGH 8.0
CVE-2025-23025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension …

Fix: 15.10.12 / 16.4.1+
Fix from $1,950 2025-01-14
W3 Total Cache HIGH 8.5
CVE-2024-12365

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page func…

Fix: 2.8.2+
Fix from $1,950 2025-01-14
W3 Total Cache MEDIUM 5.3
CVE-2024-12006

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in …

Fix: 2.8.2+
Fix from $1,600 2025-01-14
Unclassified MEDIUM 6.3
CVE-2025-0067

Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can creat…

Mitigation only
Fix from $1,600 2025-01-14
Post Smtp HIGH 8.8
CVE-2025-22800

Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Fix: 2.9.12+
Fix from $1,950 2025-01-13
Unclassified MEDIUM 5.4
CVE-2024-12204

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access …

Mitigation only
Fix from $1,600 2025-01-11
Open Social MEDIUM 5.3
CVE-2024-13312

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 1…

Fix: 12.3.10 / 12.4.9+
Fix from $1,600 2025-01-09
Download All Files MEDIUM 5.3
CVE-2024-13303

Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.…

Fix: 2.0.2+
Fix from $1,600 2025-01-09
Entity Delete Log MEDIUM 6.5
CVE-2024-13243

Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delete Log: from 0.0.0 before 1.1.…

Fix: 1.1.1+
Fix from $1,600 2025-01-09
Greenshift Animation And Page Builder Blocks MEDIUM 5.4
CVE-2024-6155

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and …

Fix: 9.0.1+
Fix from $1,600 2025-01-09
Unclassified HIGH 8.8
CVE-2024-12848

The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the 'addLibraryByArchive' func…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 8.6
CVE-2024-12542

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function …

Mitigation only
Fix from $1,950 2025-01-09
Unclassified MEDIUM 6.4
CVE-2024-11929

The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp_save_settings() functionin a…

Mitigation only
Fix from $1,600 2025-01-09
Unclassified MEDIUM 5.3
CVE-2024-43662

The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any user, although the…

Mitigation only
Fix from $1,600 2025-01-09
Unclassified HIGH 7.5
CVE-2024-11423

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates…

Mitigation only
Fix from $1,950 2025-01-08
Unclassified MEDIUM 5.3
CVE-2024-12712

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Mitigation only
Fix from $1,600 2025-01-08
Adforest MEDIUM 5.4
CVE-2024-12855

The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 's…

Fix: 5.1.8+
Fix from $1,600 2025-01-08
Webinarpress HIGH 8.8
CVE-2024-11270

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 's…

Fix: 1.33.25+
Fix from $1,950 2025-01-08
Ultimate Wordpress Toolkit HIGH 8.8
CVE-2024-11816

The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing …

Fix: 3.0.12+
Fix from $1,950 2025-01-08
Wp Extended MEDIUM 5.4
CVE-2024-11916

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missi…

Fix: 3.0.12+
Fix from $1,600 2025-01-08
Sureforms MEDIUM 5.3
CVE-2024-12713

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includ…

Fix: 1.2.3+
Fix from $1,600 2025-01-08
Unclassified MEDIUM 5.3
CVE-2025-22363

Missing Authorization vulnerability in Hermann LAHAMI Allada T-shirt Designer for Woocommerce allada-tshirt-designer-for-woocommerce.This issue affec…

Mitigation only
Fix from $1,600 2025-01-07
Unclassified MEDIUM 5.3
CVE-2024-56270

Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Retrieve Embedded Sensitive Data.This issue affects WP Secure…

Mitigation only
Fix from $1,600 2025-01-07
Unclassified HIGH 7.5
CVE-2025-22592

Missing Authorization vulnerability in 8blocks 1003 Mortgage Application 1003-mortgage-application allows Accessing Functionality Not Properly Constr…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified MEDIUM 5.3
CVE-2025-22560

Missing Authorization vulnerability in saoshyant1994 Saoshyant Page Builder saoshyant-page-builder allows Exploiting Incorrectly Configured Access Co…

Mitigation only
Fix from $1,600 2025-01-07
Unclassified MEDIUM 5.4
CVE-2025-22534

Missing Authorization vulnerability in Ella Van Durpe Slides & Presentations slide allows Exploiting Incorrectly Configured Access Control Security L…

Mitigation only
Fix from $1,600 2025-01-07
Unclassified MEDIUM 5.4
CVE-2025-22541

Missing Authorization vulnerability in etruel WP Delete Post Copies etruel-del-post-copies allows Exploiting Incorrectly Configured Access Control Se…

Mitigation only
Fix from $1,600 2025-01-07
Unclassified MEDIUM 5.4
CVE-2025-22543

Missing Authorization vulnerability in beautifultemplates ST Gallery WP st-gallery-wp allows Exploiting Incorrectly Configured Access Control Securit…

Mitigation only
Fix from $1,600 2025-01-07
Jupiter X Core MEDIUM 5.3
CVE-2024-12316

The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() f…

Fix: 4.8.6+
Fix from $1,600 2025-01-07
Unclassified MEDIUM 5.3
CVE-2024-12711

The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions l…

Mitigation only
Fix from $1,600 2025-01-07