Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zoomsounds CRITICAL 9.1
CVE-2021-4457

The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

Fix: 6.05+
Fix from $2,300 2025-06-25
Zoomsounds CRITICAL 9.8
CVE-2025-47568

Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a t…

Fix: after 6.91
Fix from $2,300 2025-05-23
Zoomsounds HIGH 7.5
CVE-2025-3431

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inclu…

Fix: after 6.91
Fix from $1,950 2025-04-08
Zoomsounds MEDIUM 5.4
CVE-2025-0839

The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insuffi…

Fix: after 6.91
Fix from $1,600 2025-04-05
Zoomsounds HIGH 8.1
CVE-2024-13776

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a…

Fix: after 6.91
Fix from $1,950 2025-04-05
Zoomsounds CRITICAL 9.8
CVE-2024-13777

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl…

Fix: after 6.91
Fix from $2,300 2025-03-05
Zoomsounds CRITICAL 9.8
CVE-2021-4449EPSS 5%

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions…

Fix: after 5.96
Fix from $2,300 2024-10-16
Zoomsounds HIGH 7.5
CVE-2021-39316EPSS 66%

The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded v…

Fix: after 6.45
Fix from $1,950 2021-08-31
Zoomsounds CRITICAL 9.8
CVE-2015-9471

The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.

Fix: after 2.0
Fix from $2,300 2019-10-10