Vulnerability index

Browse CVEs

71 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2024-13908 The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' functi… Smtp 1.2.0+ Fix from $1,9502025-03-08 HIGH 8.8 CVE-2024-35678 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft.T… Contact Form To Db 1.7.3+ Fix from $1,9502024-06-08 MEDIUM 6.1 CVE-2024-2200 The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_subject’ parameter in … Contact Form 4.2.9+ Fix from $1,6002024-04-09 HIGH 7.1 CVE-2023-45771 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.… Captcha after 1.6.8 Fix from $1,9502024-03-26 MEDIUM 6.5 CVE-2023-6821 The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP l… Error Log Viewer 1.1.3+ Fix from $1,6002024-03-18 HIGH 7.5 CVE-2023-6250 The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag Like \& Share 2.74+ Fix from $1,9502023-12-26 MEDIUM 6.1 CVE-2015-10127 A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this issue is some unknown functi… Pluscaptcha after 2.0.6 Fix from $1,6002023-12-26 MEDIUM 6.1 CVE-2014-125109 A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerability affects the function bw… Portfolio 2.28+ Fix from $1,6002023-12-26 HIGH 8.8 CVE-2012-10017 A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.04 on WordPress. It has been classified as problematic. This affects an unknown par… Portfolio 2.06+ Fix from $1,9502023-12-26 HIGH 8.8 CVE-2023-29096 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft –… Contact Form To Db after 1.7.0 Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-36527 Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebSoft.This issue affects Post to CSV by B… Post To Csv after 1.4.0 Fix from $1,9502023-11-07 CRITICAL 9.8 CVE-2023-36508 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft –… Contact Form To Db after 1.7.1 Fix from $2,3002023-10-31 MEDIUM 5.3 CVE-2023-4469 The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pr… Profile Extra Fields after 1.2.7 Fix from $1,6002023-10-06 MEDIUM 6.1 CVE-2014-125103 A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability… Twitter after 1.3.2 Fix from $1,6002023-05-31 HIGH 8.8 CVE-2012-10015 A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twtt… Twitter 2.15+ Fix from $1,9502023-05-31 HIGH 7.5 CVE-2014-125102 A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unk… Relevant 1.0.8+ Fix from $1,9502023-05-29 MEDIUM 6.1 CVE-2014-125100 A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The … Job Board Patch available Fix from $1,6002023-05-02 HIGH 8.8 CVE-2023-0765 The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulne… Gallery 4.7.0+ Fix from $1,9502023-04-17 MEDIUM 5.4 CVE-2023-0764 The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site … Gallery 4.7.0+ Fix from $1,6002023-04-17 MEDIUM 6.1 CVE-2014-125097 A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_set… Facebook Button 2.34+ Fix from $1,6002023-04-10 HIGH 8.8 CVE-2012-10012 A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the fu… Facebook Button after 2.13 Fix from $1,9502023-04-10 HIGH 8.8 CVE-2012-10010 A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page o… Contact Form Patch available Fix from $1,9502023-04-09 MEDIUM 6.1 CVE-2014-125095 A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function… Contact Form Patch available Fix from $1,6002023-04-09 MEDIUM 6.1 CVE-2013-10022 A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is … Contact Form Patch available Fix from $1,6002023-04-05 HIGH 8.8 CVE-2023-0820 The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrar… User Role 1.6.7+ Fix from $1,9502023-04-03 CRITICAL 9.8 CVE-2022-3393 The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection Post To Csv after 1.4.0 Fix from $2,3002022-10-25 MEDIUM 6.5 CVE-2021-25121 The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial o… Rating 1.6+ Fix from $1,6002022-06-20 MEDIUM 5.4 CVE-2017-20055 A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation lea… Contact Form No fix yet Fix from $1,6002022-06-16 MEDIUM 6.5 CVE-2021-24761 The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention,… Error Log Viewer 1.1.2+ Fix from $1,6002022-02-01 MEDIUM 6.1 CVE-2021-24350 The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display… Visitors Online after 0.3 Fix from $1,6002021-06-14