Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2023-49828
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solut…
Woopayments
6.5.0+
MEDIUM 5.4
CVE-2023-47777
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce …
Woocommerce
after 11.1.1
MEDIUM 5.4
CVE-2023-45050
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed…
Jetpack
after 12.8-a.1
HIGH 8.8
CVE-2022-3342
The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_ap…
Jetpack Crm
after 5.3.1
MEDIUM 5.4
CVE-2023-5057
The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role o…
Activitypub
1.0.0+
MEDIUM 5.4
CVE-2023-3746
The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role …
Activitypub
1.0.0+
HIGH 8.8
CVE-2023-2996
The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files o…
Jetpack
12.1.1+
CRITICAL 9.8
CVE-2014-125104
A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the func…
Vaultpress
1.6.1+
CRITICAL 9.8
CVE-2023-28121EPSS 87%
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an …
Woocommerce Payments
4.8.2 / 5.0.4+
MEDIUM 5.4
CVE-2022-4497
The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, wh…
Jetpack Crm
5.5.0+
HIGH 8.8
CVE-2022-45069
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
Crowdsignal Dashboard
3.0.10+
MEDIUM 5.3
CVE-2022-2034
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to acce…
Sensei Lms
4.5.0+
MEDIUM 6.1
CVE-2022-2386
The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a …
Crowdsignal Dashboard
3.0.8+
HIGH 7.5
CVE-2017-20086
A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code…
Vaultpress
No fix yet
HIGH 7.5
CVE-2021-32789EPSS 17%
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sit…
Woocommerce Blocks
2.5.16 / 2.6.2+
MEDIUM 5.3
CVE-2021-24374
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to com…
Jetpack
9.8+
MEDIUM 5.4
CVE-2021-24329
The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Sto…
Wp Super Cache
1.7.3+
HIGH 7.2
CVE-2021-24312
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of …
Wp Super Cache
1.7.3+
HIGH 7.2
CVE-2021-24209EPSS 24%
The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure a…
Wp Super Cache
1.7.2+
HIGH 8.8
CVE-2020-8215
A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a u…
Canvas
after 1.6.9
MEDIUM 6.1
CVE-2019-11843
The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Ref…
Mailpoet
3.23.2+
CRITICAL 9.8
CVE-2013-2010EPSS 74%
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
Wp Super Cache
after 1.2
HIGH 8.8
CVE-2013-2009EPSS 13%
WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
Wp Super Cache
Patch available
MEDIUM 6.1
CVE-2013-2008
WordPress Super Cache Plugin 1.3 has XSS.
Wp Super Cache
Patch available
HIGH 8.8
CVE-2013-2011EPSS 5%
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code.…
W3 Super Cache
1.3.2+
MEDIUM 6.1
CVE-2015-9359
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
Jetpack
3.4.3+
MEDIUM 6.1
CVE-2015-9357
The akismet plugin before 3.1.5 for WordPress has XSS.
Akismet
3.1.5+
HIGH 7.5
CVE-2016-10762
The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.
Camptix Event Ticketing
1.5.0+
MEDIUM 6.1
CVE-2016-10705
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
Jetpack
after 4.0.3
MEDIUM 6.1
CVE-2016-10706
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
Jetpack
4.0.3+