Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Event Monster MEDIUM 5.3
CVE-2024-11396

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up t…

Fix: 1.4.4+
Fix from $1,600 2025-01-14
Event Monster HIGH 7.5
CVE-2024-5059

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Manag…

Fix: after 1.4.0
Fix from $1,950 2024-06-21
Image Gallery HIGH 8.8
CVE-2024-35721

Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image…

Fix: 1.4.6+
Fix from $1,950 2024-06-10
Slider Responsive Slideshow HIGH 8.8
CVE-2024-35722

Missing Authorization vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow.This issue affects Slider Responsive S…

Fix: 1.4.2+
Fix from $1,950 2024-06-10
Media Slider HIGH 8.8
CVE-2024-35717

Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media …

Fix: 1.4.0+
Fix from $1,950 2024-06-10
Album Gallery HIGH 8.8
CVE-2024-35720

Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a thr…

Fix: 1.5.8+
Fix from $1,950 2024-06-10
Formula MEDIUM 6.1
CVE-2024-5613

The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'quality_customizer_notify_dismiss_acti…

Fix: 0.5.2+
Fix from $1,600 2024-06-08
Formula MEDIUM 6.1
CVE-2024-5638

The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'ti_customizer_notify_dismiss_recommend…

Fix: 0.5.2+
Fix from $1,600 2024-06-08
Event Monster HIGH 7.5
CVE-2024-1895

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up t…

Fix: 1.4.0+
Fix from $1,950 2024-04-30
Slider Responsive Slideshow HIGH 8.8
CVE-2024-1859

The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a…

Fix: 1.4.0+
Fix from $1,950 2024-03-01
Coming Soon Maintenance Mode MEDIUM 5.3
CVE-2024-1475

The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via…

Fix: 1.0.6+
Fix from $1,600 2024-02-29
Event Monster MEDIUM 5.4
CVE-2023-47525

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tic…

Fix: after 1.3.2
Fix from $1,600 2023-12-21
Blog Filter MEDIUM 5.4
CVE-2023-5291

The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.…

Fix: after 1.5.3
Fix from $1,600 2023-10-04
Blog Filter MEDIUM 5.4
CVE-2023-5295

The Comments by Startbit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and inclu…

Fix: after 1.4
Fix from $1,600 2023-09-30
Album Gallery HIGH 8.8
CVE-2023-23646

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.

Fix: 1.5.0+
Fix from $1,950 2023-07-17
Event Monster HIGH 7.2
CVE-2022-3720

The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to…

Fix: 1.2.0+
Fix from $1,950 2022-11-21
Weather Effect MEDIUM 5.4
CVE-2021-24683

The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them,…

Fix: 1.3.4+
Fix from $1,600 2021-10-11
Grid Gallery MEDIUM 5.4
CVE-2021-24529

The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding …

Fix: 1.2.5+
Fix from $1,600 2021-08-23
Contact Form Widget CRITICAL 9.8
CVE-2019-17072

The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.

Mitigation only
Fix from $2,300 2019-10-10