Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mortgage Calculator HIGH 8.8
CVE-2025-48136

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator …

Fix: after 2.0.12
Fix from $1,950 2025-05-16
Estatik CRITICAL 9.8
CVE-2023-6049

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users…

Fix: 4.1.1+
Fix from $2,300 2024-01-15
Estatik MEDIUM 6.5
CVE-2023-6048

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting an…

Fix: 4.1.1+
Fix from $1,600 2024-01-15
Estatik MEDIUM 6.1
CVE-2023-6050

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting the…

Fix: 4.1.1+
Fix from $1,600 2024-01-15
Estatik Mortgage Calculator MEDIUM 6.1
CVE-2023-28490

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.

Fix: after 2.0.7
Fix from $1,600 2023-09-27
Estatik Mortgage Calculator MEDIUM 6.1
CVE-2023-40601

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.

Fix: after 2.0.7
Fix from $1,600 2023-09-06
Estatik HIGH 7.5
CVE-2016-10958

The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.

Fix: 2.3.0+
Fix from $1,950 2019-09-16
Estatik MEDIUM 6.5
CVE-2016-10959

The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin…

Fix: 2.3.1+
Fix from $1,600 2019-09-16