Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wpdiscuz MEDIUM 6.1
CVE-2026-22210

wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 5.5
CVE-2026-22209

wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 5.4
CVE-2026-22215

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthor…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 5.3
CVE-2026-22216

wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 6.5
CVE-2026-22202

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email addr…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 5.3
CVE-2026-22201

wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban e…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 5.3
CVE-2026-22204

wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious da…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz CRITICAL 9.9
CVE-2026-22192

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged m…

Fix: 7.6.47+
Fix from $2,300 2026-03-13
Wpdiscuz HIGH 7.5
CVE-2026-22193

wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escapi…

Fix: 7.6.47+
Fix from $1,950 2026-03-13
Wpdiscuz HIGH 7.5
CVE-2026-22199

Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenti…

Fix: 7.6.47+
Fix from $1,950 2026-03-13
Wpdiscuz MEDIUM 5.2
CVE-2026-22191

Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary AngularJS expressions by exploiting…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz HIGH 7.5
CVE-2026-22182

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by…

Fix: 7.6.47+
Fix from $1,950 2026-03-13
Wpdiscuz MEDIUM 5.4
CVE-2026-22183

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated use…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpforo Forum CRITICAL 9.8
CVE-2026-28562

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql…

Fix: 2.4.15+
Fix from $2,300 2026-02-28
Wpforo Forum MEDIUM 6.5
CVE-2026-28557

wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment v…

Fix: 2.4.16+
Fix from $1,600 2026-02-28
Wpforo Forum MEDIUM 5.4
CVE-2026-28556

wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via…

Fix: 2.4.16+
Fix from $1,600 2026-02-28
Wpforo Forum MEDIUM 5.4
CVE-2026-28558

wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars…

Fix: 2.4.16+
Fix from $1,600 2026-02-28
Wpforo Forum MEDIUM 5.3
CVE-2026-28559

wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topic…

Fix: 2.4.16+
Fix from $1,600 2026-02-28
Wpforo Forum MEDIUM 6.5
CVE-2025-0764

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Member…

Fix: 2.4.2+
Fix from $1,600 2025-02-28
Wpdiscuz HIGH 7.3
CVE-2023-46309

Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This …

Fix: 7.6.11+
Fix from $1,950 2025-01-02
Wpdiscuz HIGH 8.8
CVE-2023-45760

Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This …

Fix: 7.6.4+
Fix from $1,950 2025-01-02
Wpforo Forum MEDIUM 5.4
CVE-2023-47869

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This …

Fix: 2.2.6+
Fix from $1,600 2024-12-09
Wpdiscuz CRITICAL 9.8
CVE-2024-9488

The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insu…

Fix: 7.6.25+
Fix from $2,300 2024-10-25
Wpforo Forum HIGH 7.5
CVE-2024-43289

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a thro…

Fix: 2.3.5+
Fix from $1,950 2024-08-26
Wpforo Forum HIGH 8.1
CVE-2024-43288

Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.

Fix: 2.3.5+
Fix from $1,950 2024-08-18
Wpdiscuz MEDIUM 6.1
CVE-2024-6704

The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of f…

Fix: 7.6.22+
Fix from $1,600 2024-08-02
Wpforo Forum MEDIUM 5.4
CVE-2022-38055

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.Thi…

Fix: 2.1.0+
Fix from $1,600 2024-06-21
Wpdiscuz MEDIUM 5.4
CVE-2024-35681

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in gVectors Team wpDiscuz allows Stored XSS…

Fix: 7.6.19+
Fix from $1,600 2024-06-08
Wpdiscuz MEDIUM 6.1
CVE-2023-46310

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpDiscuz allows Code Injection.This issu…

Fix: 7.6.11+
Fix from $1,600 2024-06-04
Wpforo Forum MEDIUM 6.5
CVE-2024-3200

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and in…

Fix: 2.3.4+
Fix from $1,600 2024-06-01