Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Quiz Maker MEDIUM 6.5
CVE-2024-22027

Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of…

Fix: 6.5.0.6+
Fix from $1,600 2024-01-12
Quiz Maker MEDIUM 6.1
CVE-2023-6166

The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site S…

Fix: 6.4.9.5+
Fix from $1,600 2023-12-26
Quiz Maker MEDIUM 5.3
CVE-2023-6155

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticat…

Fix: 6.4.9.5+
Fix from $1,600 2023-12-26
Poll Maker HIGH 7.5
CVE-2023-34013

Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best Word…

Fix: after 4.6.2
Fix from $1,950 2023-11-13
Photo Gallery HIGH 8.8
CVE-2023-39917

Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.2.6 versions.

Fix: after 5.2.6
Fix from $1,950 2023-10-03
Poll Maker MEDIUM 6.1
CVE-2023-41871

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions.

Fix: after 4.7.0
Fix from $1,600 2023-09-25
Photo Gallery MEDIUM 6.1
CVE-2023-32107

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 vers…

Fix: 5.1.4+
Fix from $1,600 2023-08-18
Popup Box MEDIUM 6.1
CVE-2023-27414

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions.

Fix: 3.4.5+
Fix from $1,600 2023-06-21
Photo Gallery MEDIUM 6.1
CVE-2023-2568

The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected …

Fix: 5.1.7+
Fix from $1,600 2023-06-12
Quiz Maker MEDIUM 6.1
CVE-2023-2571

The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-…

Fix: 6.4.2.7+
Fix from $1,600 2023-06-05
Survey Maker MEDIUM 6.1
CVE-2023-2572

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-…

Fix: 3.4.7+
Fix from $1,600 2023-06-05
Survey Maker HIGH 8.8
CVE-2023-23490

The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its…

Fix: 3.1.2+
Fix from $1,950 2023-01-20
Survey Maker MEDIUM 6.1
CVE-2023-0038

The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up…

Fix: after 3.1.3
Fix from $1,600 2023-01-03
Personal Dictionary CRITICAL 9.8
CVE-2022-1013EPSS 8%

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL st…

Fix: 1.3.4+
Fix from $2,300 2022-05-09
Popup Like Box MEDIUM 6.1
CVE-2022-0641

The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, le…

Fix: 3.6.1+
Fix from $1,600 2022-03-28
Survey Maker MEDIUM 6.1
CVE-2021-26256

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).

Fix: after 2.0.6
Fix from $1,600 2022-02-21
Secure Copy Content Protection And Content Locking CRITICAL 9.8
CVE-2021-24931EPSS 79%

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_ex…

Fix: 2.8.2+
Fix from $2,300 2021-12-06
Poll Maker HIGH 7.5
CVE-2021-24651

The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the res…

Fix: 3.4.2+
Fix from $1,950 2021-10-11
Poll Maker MEDIUM 6.1
CVE-2021-34635

The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-…

Fix: after 3.2.8
Fix from $1,600 2021-08-02
Poll Maker HIGH 7.2
CVE-2021-24483

The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate …

Fix: 3.2.1+
Fix from $1,950 2021-08-02
Secure Copy Content Protection And Content Locking HIGH 7.2
CVE-2021-24484

The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate …

Fix: 2.6.7+
Fix from $1,950 2021-08-02
Portfolio Responsive Gallery HIGH 8.8
CVE-2021-24457

The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive…

Fix: 1.1.8+
Fix from $1,950 2021-08-02
Popup Box HIGH 8.8
CVE-2021-24458

The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the or…

Fix: 2.3.4+
Fix from $1,950 2021-08-02
Survey Maker HIGH 8.8
CVE-2021-24459

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter…

Fix: 1.5.6+
Fix from $1,950 2021-08-02
Popup Box HIGH 8.8
CVE-2021-24460

The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby param…

Fix: 3.5.3+
Fix from $1,950 2021-08-02
Faq Builder HIGH 8.8
CVE-2021-24461

The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it …

Fix: 1.3.6+
Fix from $1,950 2021-08-02
Photo Gallery HIGH 8.8
CVE-2021-24462

The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did n…

Fix: 4.4.4+
Fix from $1,950 2021-08-02
Image Slider HIGH 8.8
CVE-2021-24463

The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate…

Fix: 2.5.0+
Fix from $1,950 2021-08-02
Quiz Maker HIGH 7.2
CVE-2021-24456

The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL stateme…

Fix: 6.2.0.9+
Fix from $1,950 2021-08-02
Photo Gallery CRITICAL 9.8
CVE-2016-10921

The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.

Fix: 1.0.1+
Fix from $2,300 2019-08-22