Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Givewp MEDIUM 6.1
CVE-2024-27987

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP GiveWP give.This issue affects GiveWP…

Fix: 3.4.0+
Fix from $1,600 2024-03-15
Givewp MEDIUM 5.4
CVE-2023-51415

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising…

Fix: after 3.2.2
Fix from $1,600 2024-02-10
Givewp CRITICAL 9.8
CVE-2023-0224

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attacker…

Fix: 2.24.1+
Fix from $2,300 2024-01-16
Givewp MEDIUM 5.4
CVE-2023-4247

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incor…

Fix: after 2.33.3
Fix from $1,600 2024-01-11
Givewp CRITICAL 9.8
CVE-2023-32513

Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plug…

Fix: after 2.25.3
Fix from $2,300 2023-12-28
Givewp MEDIUM 6.5
CVE-2022-40312

Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plu…

Fix: after 2.25.1
Fix from $1,600 2023-12-18
Givewp CRITICAL 9.8
CVE-2023-22719

Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1.

Fix: after 2.25.1
Fix from $2,300 2023-11-07
Givewp HIGH 8.8
CVE-2023-25450

Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2.25.1 versions.

Fix: 2.25.2+
Fix from $1,950 2023-06-15
Givewp MEDIUM 5.4
CVE-2023-23668

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP plugin <= 2.25.1 versions.

Fix: 2.25.2+
Fix from $1,600 2023-05-08
Givewp MEDIUM 5.4
CVE-2022-4448

The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post wh…

Fix: 2.24.0+
Fix from $1,600 2023-02-13
Givewp MEDIUM 6.5
CVE-2022-2260

The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dat…

Fix: 2.21.3+
Fix from $1,600 2022-08-01
Givewp HIGH 7.2
CVE-2022-28700

Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

Fix: 2.21.0+
Fix from $1,950 2022-07-21
Givewp MEDIUM 5.3
CVE-2022-2117

The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-A…

Fix: after 2.20.2
Fix from $1,600 2022-07-18
Givewp MEDIUM 6.1
CVE-2022-0252

The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard,…

Fix: 2.17.3+
Fix from $1,600 2022-02-21
Givewp MEDIUM 6.1
CVE-2021-25099

The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthen…

Fix: 2.17.3+
Fix from $1,600 2022-02-21
Givewp MEDIUM 6.1
CVE-2021-25100

The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, …

Fix: 2.17.3+
Fix from $1,600 2022-02-21
Givewp MEDIUM 6.1
CVE-2021-24213

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability i…

Fix: 2.10.0+
Fix from $1,600 2021-04-12
Givewp MEDIUM 5.3
CVE-2020-20627

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

Fix: after 2.5.9
Fix from $1,600 2020-08-31
Givewp HIGH 7.5
CVE-2019-20360

A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiabl…

Fix: 2.5.5+
Fix from $1,950 2020-01-08
Givewp MEDIUM 5.4
CVE-2019-15317

The give plugin before 2.4.7 for WordPress has XSS via a donor name.

Fix: 2.4.7+
Fix from $1,600 2019-08-22
Givewp CRITICAL 9.8
CVE-2019-13578

A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability wou…

Fix: after 2.5.0
Fix from $2,300 2019-08-15
Givewp MEDIUM 6.1
CVE-2019-9909

The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.

Fix: 2.3.1+
Fix from $1,600 2019-03-22