Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2025-6200 The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page… Geodirectory 2.8.120+ Fix from $1,6002025-07-11 MEDIUM 5.4 CVE-2024-13590 The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, a… Ketchup Shortcodes 0.2.1+ Fix from $1,6002025-01-22 MEDIUM 5.4 CVE-2024-56259 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored X… Geodirectory 2.3.85+ Fix from $1,6002025-01-02 HIGH 8.8 CVE-2024-43981 Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control S… Geodirectory 2.3.71+ Fix from $1,9502024-11-01 HIGH 8.8 CVE-2024-43973 Missing Authorization vulnerability in Stiofan GetPaid invoicing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a… Getpaid 2.8.12+ Fix from $1,9502024-11-01 MEDIUM 5.4 CVE-2024-50437 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored X… Geodirectory 2.3.81+ Fix from $1,6002024-10-28 HIGH 8.8 CVE-2024-43145 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects Geo… Geodirectory 2.3.62+ Fix from $1,9502024-08-18 HIGH 7.5 CVE-2024-6477 The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers … Userswp 1.2.12+ Fix from $1,9502024-08-03 CRITICAL 9.8 CVE-2024-6265 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to ti… Userswp 1.2.11+ Fix from $2,3002024-06-29 MEDIUM 5.4 CVE-2024-3732 The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… Geodirectory 2.3.49+ Fix from $1,6002024-04-23 MEDIUM 6.4 CVE-2024-2423 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to St… Userswp 1.2.7+ Fix from $1,6002024-04-09 HIGH 7.2 CVE-2023-50845 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins … Geodirectory after 2.3.28 Fix from $1,9502023-12-28 HIGH 8.8 CVE-2022-47442 Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9. Userswp 1.2.3.10+ Fix from $1,9502023-11-07 MEDIUM 5.4 CVE-2022-4775 The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page… Geodirectory 2.2.22+ Fix from $1,6002023-01-23 MEDIUM 5.4 CVE-2021-24720 The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS). Geodirectory 2.1.1.3+ Fix from $1,6002021-10-11 CRITICAL 9.8 CVE-2021-24361 In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its … Location Manager 2.1.0.10+ Fix from $2,3002021-06-21 MEDIUM 5.4 CVE-2021-24369 In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Tex… Getpaid 2.3.4+ Fix from $1,6002021-06-21