Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.6 CVE-2024-9529 The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress pl… Advanced Custom Fields 6.3.9+ Fix from $1,6002024-11-15 MEDIUM 6.5 CVE-2024-4565 The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom fie… Advanced Custom Fields 6.3+ Fix from $1,6002024-06-20 MEDIUM 5.4 CVE-2023-6701 The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and… Advanced Custom Fields after 6.2.4 Fix from $1,6002024-02-05 HIGH 7.5 CVE-2022-40696 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom… Advanced Custom Fields after 6.0.2 Fix from $1,9502024-01-08 MEDIUM 5.4 CVE-2023-40068 Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a … Advanced Custom Fields after 6.1.7 Fix from $1,6002023-08-21 MEDIUM 6.1 CVE-2023-30777EPSS 39% Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5… Advanced Custom Fields 6.1.6+ Fix from $1,6002023-05-10 HIGH 8.8 CVE-2023-1196 The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which coul… Advanced Custom Fields 5.12.5 / 6.1.0+ Fix from $1,9502023-05-02 HIGH 8.8 CVE-2022-2594 The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to … Advanced Custom Fields 5.12.3+ Fix from $1,9502022-08-22 MEDIUM 6.5 CVE-2022-23183 Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows… Advanced Custom Fields 5.12.1+ Fix from $1,6002022-03-31 MEDIUM 6.5 CVE-2021-20867 Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in … Advanced Custom Fields 5.11+ Fix from $1,6002021-12-13 HIGH 7.5 CVE-2021-20865 Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in … Advanced Custom Fields 5.11+ Fix from $1,9502021-12-13 MEDIUM 6.5 CVE-2021-20866 Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in … Advanced Custom Fields 5.11+ Fix from $1,6002021-12-13 MEDIUM 6.1 CVE-2021-24241 The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, lea… Advanced Custom Fields 5.9.1+ Fix from $1,6002021-04-22 MEDIUM 6.1 CVE-2020-36172 The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS. Advanced Custom Fields 5.8.12+ Fix from $1,6002021-01-06 CRITICAL 9.8 CVE-2015-9479 The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upl… Acf Fronted Display after 2015-07-03 Fix from $2,3002019-10-10 MEDIUM 5.4 CVE-2018-20986 The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors. Advanced Custom Fields 5.7.8+ Fix from $1,6002019-08-22