Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wpforo Forum CRITICAL 9.8
CVE-2023-47868

Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.…

Fix: 2.2.4+
Fix from $2,300 2024-05-17
Wpdiscuz MEDIUM 5.4
CVE-2024-2477

The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions …

Fix: 7.6.16+
Fix from $1,600 2024-04-23
Wpdiscuz MEDIUM 6.5
CVE-2023-46311

Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a …

Fix: 7.6.4+
Fix from $1,600 2023-12-20
Woodiscuz Woocommerce Comments HIGH 8.8
CVE-2023-49759

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments…

Fix: after 2.3.0
Fix from $1,950 2023-12-18
Wpforo Forum HIGH 8.8
CVE-2023-47870

Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access…

Fix: after 2.2.6
Fix from $1,950 2023-11-30
Wpforo Forum MEDIUM 5.4
CVE-2023-47872

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.Th…

Fix: after 2.2.3
Fix from $1,600 2023-11-30
Wpdiscuz HIGH 8.8
CVE-2023-47775

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.

Fix: 7.6.12+
Fix from $1,950 2023-11-22
Wpdiscuz MEDIUM 6.1
CVE-2023-47185

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.

Fix: after 7.6.11
Fix from $1,600 2023-11-06
Wpdiscuz MEDIUM 5.3
CVE-2023-3869

The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi…

Fix: after 7.6.3
Fix from $1,600 2023-10-20
Wpdiscuz MEDIUM 5.3
CVE-2023-3998

The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in…

Fix: after 7.6.3
Fix from $1,600 2023-10-20
Wpforo Forum MEDIUM 6.1
CVE-2023-2309

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripti…

Fix: 2.1.9+
Fix from $1,600 2023-07-24
Wpforo Forum HIGH 8.8
CVE-2023-2249EPSS 61%

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, a…

Fix: after 2.1.7
Fix from $1,950 2023-06-09
Wpdiscuz HIGH 8.8
CVE-2022-43492

Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.

Mitigation only
Fix from $1,950 2022-11-18
Wpforo Forum HIGH 8.8
CVE-2022-40200

Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

Fix: after 2.0.9
Fix from $1,950 2022-11-17
Wpforo Forum HIGH 8.8
CVE-2022-40192

Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

Fix: after 2.0.9
Fix from $1,950 2022-11-17
Wpforo Forum MEDIUM 5.4
CVE-2022-40632

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.

Fix: after 2.0.5
Fix from $1,600 2022-11-08
Wpforo Forum HIGH 8.8
CVE-2022-38144

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.

Fix: after 2.0.5
Fix from $1,950 2022-09-09
Wpdiscuz HIGH 7.5
CVE-2022-23984

Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).

Fix: after 7.3.11
Fix from $1,950 2022-02-21
Wpforo Forum MEDIUM 6.1
CVE-2021-24406

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect…

Fix: 1.9.7+
Fix from $1,600 2021-07-06
Wpdiscuz CRITICAL 10.0
CVE-2020-24186EPSS 95%

A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to u…

Fix: after 7.0.4
Fix from $2,300 2020-08-24
Wpdiscuz CRITICAL 9.8
CVE-2020-13640EPSS 13%

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via t…

Fix: after 5.3.5
Fix from $2,300 2020-06-18
Wpforo HIGH 8.8
CVE-2019-19109

The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.

No fix yet
Fix from $1,950 2020-06-15
Wpforo MEDIUM 6.1
CVE-2019-19111

The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.

No fix yet
Fix from $1,600 2020-06-15
Wpforo MEDIUM 6.1
CVE-2019-19112

The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.

No fix yet
Fix from $1,600 2020-06-15
Wpforo Forum CRITICAL 9.8
CVE-2018-16613

An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privileg…

Fix: 1.5.2+
Fix from $2,300 2019-06-19
Wpforo Forum MEDIUM 6.1
CVE-2018-11709

wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Si…

Fix: 1.4.12+
Fix from $1,600 2018-06-04
Wpforo CRITICAL 9.8
CVE-2018-11515

The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.

Fix: 1.4.5+
Fix from $2,300 2018-05-28