Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-22027 Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of… Quiz Maker 6.5.0.6+ Fix from $1,6002024-01-12 MEDIUM 6.1 CVE-2023-6166 The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site S… Quiz Maker 6.4.9.5+ Fix from $1,6002023-12-26 MEDIUM 5.3 CVE-2023-6155 The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticat… Quiz Maker 6.4.9.5+ Fix from $1,6002023-12-26 HIGH 7.5 CVE-2023-34013 Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best Word… Poll Maker after 4.6.2 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-39917 Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.2.6 versions. Photo Gallery after 5.2.6 Fix from $1,9502023-10-03 MEDIUM 6.1 CVE-2023-41871 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions. Poll Maker after 4.7.0 Fix from $1,6002023-09-25 MEDIUM 6.1 CVE-2023-32107 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 vers… Photo Gallery 5.1.4+ Fix from $1,6002023-08-18 MEDIUM 6.1 CVE-2023-27414 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions. Popup Box 3.4.5+ Fix from $1,6002023-06-21 MEDIUM 6.1 CVE-2023-2568 The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected … Photo Gallery 5.1.7+ Fix from $1,6002023-06-12 MEDIUM 6.1 CVE-2023-2571 The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-… Quiz Maker 6.4.2.7+ Fix from $1,6002023-06-05 MEDIUM 6.1 CVE-2023-2572 The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-… Survey Maker 3.4.7+ Fix from $1,6002023-06-05 HIGH 8.8 CVE-2023-23490 The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its… Survey Maker 3.1.2+ Fix from $1,9502023-01-20 MEDIUM 6.1 CVE-2023-0038 The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up… Survey Maker after 3.1.3 Fix from $1,6002023-01-03 CRITICAL 9.8 CVE-2022-1013EPSS 8% The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL st… Personal Dictionary 1.3.4+ Fix from $2,3002022-05-09 MEDIUM 6.1 CVE-2022-0641 The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, le… Popup Like Box 3.6.1+ Fix from $1,6002022-03-28 MEDIUM 6.1 CVE-2021-26256 Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6). Survey Maker after 2.0.6 Fix from $1,6002022-02-21 CRITICAL 9.8 CVE-2021-24931EPSS 79% The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_ex… Secure Copy Content Protection And Content Locking 2.8.2+ Fix from $2,3002021-12-06 HIGH 7.5 CVE-2021-24651 The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the res… Poll Maker 3.4.2+ Fix from $1,9502021-10-11 MEDIUM 6.1 CVE-2021-34635 The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-… Poll Maker after 3.2.8 Fix from $1,6002021-08-02 HIGH 7.2 CVE-2021-24483 The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate … Poll Maker 3.2.1+ Fix from $1,9502021-08-02 HIGH 7.2 CVE-2021-24484 The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate … Secure Copy Content Protection And Content Locking 2.6.7+ Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-24457 The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive… Portfolio Responsive Gallery 1.1.8+ Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-24458 The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the or… Popup Box 2.3.4+ Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-24459 The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter… Survey Maker 1.5.6+ Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-24460 The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby param… Popup Box 3.5.3+ Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-24461 The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it … Faq Builder 1.3.6+ Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-24462 The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did n… Photo Gallery 4.4.4+ Fix from $1,9502021-08-02 HIGH 8.8 CVE-2021-24463 The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate… Image Slider 2.5.0+ Fix from $1,9502021-08-02 HIGH 7.2 CVE-2021-24456 The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL stateme… Quiz Maker 6.2.0.9+ Fix from $1,9502021-08-02 CRITICAL 9.8 CVE-2016-10921 The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection. Photo Gallery 1.0.1+ Fix from $2,3002019-08-22