Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Music Store MEDIUM 6.1
CVE-2016-10992

The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.

Fix: after 1.0.141
Fix from $1,600 2019-09-17
Sell Downloads HIGH 7.5
CVE-2015-9348

The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.

Fix: 1.0.8+
Fix from $1,950 2019-08-27
Polls Cp MEDIUM 6.1
CVE-2014-10395

The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.

Fix: 1.0.1+
Fix from $1,600 2019-08-27
Polls Cp MEDIUM 6.1
CVE-2015-9346

The cp-polls plugin before 1.0.5 for WordPress has XSS.

Fix: 1.0.5+
Fix from $1,600 2019-08-27
Appointment Booking Calendar CRITICAL 9.8
CVE-2016-10916

The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.

Fix: 1.1.24+
Fix from $2,300 2019-08-22
Booking Calendar Contact Form CRITICAL 9.8
CVE-2016-10909

The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.

Fix: 1.0.24+
Fix from $2,300 2019-08-21
Booking Calendar Contact Form MEDIUM 6.1
CVE-2016-10908

The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.

Fix: 1.0.24+
Fix from $1,600 2019-08-21
Cp Contact Form With Paypal MEDIUM 6.1
CVE-2019-14784

The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.

Fix: 1.2.98+
Fix from $1,600 2019-08-15
Contact Form Email HIGH 8.8
CVE-2018-20964

The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.

Fix: 1.2.66+
Fix from $1,950 2019-08-13
Contact Form Email MEDIUM 6.1
CVE-2018-20963

The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.

Fix: 1.2.66+
Fix from $1,600 2019-08-13
Appointment Booking Calendar MEDIUM 6.1
CVE-2019-14791

The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.

No fix yet
Fix from $1,600 2019-08-09
Cp Contact Form With Paypal MEDIUM 5.4
CVE-2019-14785

The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form…

Fix: 1.2.99+
Fix from $1,600 2019-08-09
Contact Form Email MEDIUM 6.1
CVE-2019-9646

The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom …

Fix: 1.2.66+
Fix from $1,600 2019-03-10
Payment Form For Paypal Pro MEDIUM 6.1
CVE-2015-7666

Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_messag…

Fix: after 1.0.1
Fix from $1,600 2017-12-27
Cp Contact Form With Paypal HIGH 8.8
CVE-2015-9233

The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contac…

Fix: 1.1.6+
Fix from $1,950 2017-09-30
Appointment Booking Calendar HIGH 7.5
CVE-2015-7319

SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPre…

Fix: after 1.1.7
Fix from $1,950 2015-09-29