Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-47868 Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.… Wpforo Forum 2.2.4+ Fix from $2,3002024-05-17 MEDIUM 5.4 CVE-2024-2477 The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions … Wpdiscuz 7.6.16+ Fix from $1,6002024-04-23 MEDIUM 6.5 CVE-2023-46311 Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a … Wpdiscuz 7.6.4+ Fix from $1,6002023-12-20 HIGH 8.8 CVE-2023-49759 Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments… Woodiscuz Woocommerce Comments after 2.3.0 Fix from $1,9502023-12-18 HIGH 8.8 CVE-2023-47870 Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access… Wpforo Forum after 2.2.6 Fix from $1,9502023-11-30 MEDIUM 5.4 CVE-2023-47872 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.Th… Wpforo Forum after 2.2.3 Fix from $1,6002023-11-30 HIGH 8.8 CVE-2023-47775 Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. Wpdiscuz 7.6.12+ Fix from $1,9502023-11-22 MEDIUM 6.1 CVE-2023-47185 Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. Wpdiscuz after 7.6.11 Fix from $1,6002023-11-06 MEDIUM 5.3 CVE-2023-3869 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi… Wpdiscuz after 7.6.3 Fix from $1,6002023-10-20 MEDIUM 5.3 CVE-2023-3998 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in… Wpdiscuz after 7.6.3 Fix from $1,6002023-10-20 MEDIUM 6.1 CVE-2023-2309 The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripti… Wpforo Forum 2.1.9+ Fix from $1,6002023-07-24 HIGH 8.8 CVE-2023-2249EPSS 61% The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, a… Wpforo Forum after 2.1.7 Fix from $1,9502023-06-09 HIGH 8.8 CVE-2022-43492 Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress. Wpdiscuz Mitigation only Fix from $1,9502022-11-18 HIGH 8.8 CVE-2022-40200 Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. Wpforo Forum after 2.0.9 Fix from $1,9502022-11-17 HIGH 8.8 CVE-2022-40192 Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. Wpforo Forum after 2.0.9 Fix from $1,9502022-11-17 MEDIUM 5.4 CVE-2022-40632 Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion. Wpforo Forum after 2.0.5 Fix from $1,6002022-11-08 HIGH 8.8 CVE-2022-38144 Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress. Wpforo Forum after 2.0.5 Fix from $1,9502022-09-09 HIGH 7.5 CVE-2022-23984 Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). Wpdiscuz after 7.3.11 Fix from $1,9502022-02-21 MEDIUM 6.1 CVE-2021-24406 The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect… Wpforo Forum 1.9.7+ Fix from $1,6002021-07-06 CRITICAL 10.0 CVE-2020-24186EPSS 95% A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to u… Wpdiscuz after 7.0.4 Fix from $2,3002020-08-24 CRITICAL 9.8 CVE-2020-13640EPSS 13% A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via t… Wpdiscuz after 5.3.5 Fix from $2,3002020-06-18 HIGH 8.8 CVE-2019-19109 The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. Wpforo No fix yet Fix from $1,9502020-06-15 MEDIUM 6.1 CVE-2019-19111 The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter. Wpforo No fix yet Fix from $1,6002020-06-15 MEDIUM 6.1 CVE-2019-19112 The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php. Wpforo No fix yet Fix from $1,6002020-06-15 CRITICAL 9.8 CVE-2018-16613 An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privileg… Wpforo Forum 1.5.2+ Fix from $2,3002019-06-19 MEDIUM 6.1 CVE-2018-11709 wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Si… Wpforo Forum 1.4.12+ Fix from $1,6002018-06-04 CRITICAL 9.8 CVE-2018-11515 The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. Wpforo 1.4.5+ Fix from $2,3002018-05-28