Vulnerability index

Browse CVEs

63 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-49828 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solut… Woopayments 6.5.0+ Fix from $1,6002023-12-14 MEDIUM 5.4 CVE-2023-47777 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce … Woocommerce after 11.1.1 Fix from $1,6002023-11-30 MEDIUM 5.4 CVE-2023-45050 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed… Jetpack after 12.8-a.1 Fix from $1,6002023-11-30 HIGH 8.8 CVE-2022-3342 The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_ap… Jetpack Crm after 5.3.1 Fix from $1,9502023-10-20 MEDIUM 5.4 CVE-2023-5057 The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role o… Activitypub 1.0.0+ Fix from $1,6002023-10-16 MEDIUM 5.4 CVE-2023-3746 The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role … Activitypub 1.0.0+ Fix from $1,6002023-10-16 HIGH 8.8 CVE-2023-2996 The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files o… Jetpack 12.1.1+ Fix from $1,9502023-06-27 CRITICAL 9.8 CVE-2014-125104 A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the func… Vaultpress 1.6.1+ Fix from $2,3002023-06-01 CRITICAL 9.8 CVE-2023-28121EPSS 87% An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an … Woocommerce Payments 4.8.2 / 5.0.4+ Fix from $2,3002023-04-12 MEDIUM 5.4 CVE-2022-4497 The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, wh… Jetpack Crm 5.5.0+ Fix from $1,6002023-01-09 HIGH 8.8 CVE-2022-45069 Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress. Crowdsignal Dashboard 3.0.10+ Fix from $1,9502022-11-17 MEDIUM 5.3 CVE-2022-2034 The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to acce… Sensei Lms 4.5.0+ Fix from $1,6002022-08-29 MEDIUM 6.1 CVE-2022-2386 The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a … Crowdsignal Dashboard 3.0.8+ Fix from $1,6002022-08-08 HIGH 7.5 CVE-2017-20086 A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code… Vaultpress No fix yet Fix from $1,9502022-06-23 HIGH 7.5 CVE-2021-32789EPSS 17% woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sit… Woocommerce Blocks 2.5.16 / 2.6.2+ Fix from $1,9502021-07-26 MEDIUM 5.3 CVE-2021-24374 The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to com… Jetpack 9.8+ Fix from $1,6002021-06-21 MEDIUM 5.4 CVE-2021-24329 The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Sto… Wp Super Cache 1.7.3+ Fix from $1,6002021-06-01 HIGH 7.2 CVE-2021-24312 The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of … Wp Super Cache 1.7.3+ Fix from $1,9502021-06-01 HIGH 7.2 CVE-2021-24209EPSS 24% The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure a… Wp Super Cache 1.7.2+ Fix from $1,9502021-04-05 HIGH 8.8 CVE-2020-8215 A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a u… Canvas after 1.6.9 Fix from $1,9502020-07-20 MEDIUM 6.1 CVE-2019-11843 The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Ref… Mailpoet 3.23.2+ Fix from $1,6002020-06-02 CRITICAL 9.8 CVE-2013-2010EPSS 74% WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability Wp Super Cache after 1.2 Fix from $2,3002020-02-12 HIGH 8.8 CVE-2013-2009EPSS 13% WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution Wp Super Cache Patch available Fix from $1,9502020-02-07 MEDIUM 6.1 CVE-2013-2008 WordPress Super Cache Plugin 1.3 has XSS. Wp Super Cache Patch available Fix from $1,6002020-02-07 HIGH 8.8 CVE-2013-2011EPSS 5% WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code.… W3 Super Cache 1.3.2+ Fix from $1,9502019-12-26 MEDIUM 6.1 CVE-2015-9359 The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg(). Jetpack 3.4.3+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9357 The akismet plugin before 3.1.5 for WordPress has XSS. Akismet 3.1.5+ Fix from $1,6002019-08-28 HIGH 7.5 CVE-2016-10762 The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used. Camptix Event Ticketing 1.5.0+ Fix from $1,9502019-07-18 MEDIUM 6.1 CVE-2016-10705 The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module. Jetpack after 4.0.3 Fix from $1,6002018-01-12 MEDIUM 6.1 CVE-2016-10706 The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. Jetpack 4.0.3+ Fix from $1,6002018-01-12