Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.9
CVE-2025-6200
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page…
Geodirectory
2.8.120+
MEDIUM 5.4
CVE-2024-13590
The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, a…
Ketchup Shortcodes
0.2.1+
MEDIUM 5.4
CVE-2024-56259
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored X…
Geodirectory
2.3.85+
HIGH 8.8
CVE-2024-43981
Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control S…
Geodirectory
2.3.71+
HIGH 8.8
CVE-2024-43973
Missing Authorization vulnerability in Stiofan GetPaid invoicing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…
Getpaid
2.8.12+
MEDIUM 5.4
CVE-2024-50437
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored X…
Geodirectory
2.3.81+
HIGH 8.8
CVE-2024-43145
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects Geo…
Geodirectory
2.3.62+
HIGH 7.5
CVE-2024-6477
The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers …
Userswp
1.2.12+
CRITICAL 9.8
CVE-2024-6265
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to ti…
Userswp
1.2.11+
MEDIUM 5.4
CVE-2024-3732
The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via…
Geodirectory
2.3.49+
MEDIUM 6.4
CVE-2024-2423
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to St…
Userswp
1.2.7+
HIGH 7.2
CVE-2023-50845
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins …
Geodirectory
after 2.3.28
HIGH 8.8
CVE-2022-47442
Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.
Userswp
1.2.3.10+
MEDIUM 5.4
CVE-2022-4775
The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page…
Geodirectory
2.2.22+
MEDIUM 5.4
CVE-2021-24720
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
Geodirectory
2.1.1.3+
CRITICAL 9.8
CVE-2021-24361
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its …
Location Manager
2.1.0.10+
MEDIUM 5.4
CVE-2021-24369
In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Tex…
Getpaid
2.3.4+