Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2023-47868
Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.…
Wpforo Forum
2.2.4+
MEDIUM 5.4
CVE-2024-2477
The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions …
Wpdiscuz
7.6.16+
MEDIUM 6.5
CVE-2023-46311
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a …
Wpdiscuz
7.6.4+
HIGH 8.8
CVE-2023-49759
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments…
Woodiscuz Woocommerce Comments
after 2.3.0
HIGH 8.8
CVE-2023-47870
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access…
Wpforo Forum
after 2.2.6
MEDIUM 5.4
CVE-2023-47872
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.Th…
Wpforo Forum
after 2.2.3
HIGH 8.8
CVE-2023-47775
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.
Wpdiscuz
7.6.12+
MEDIUM 6.1
CVE-2023-47185
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.
Wpdiscuz
after 7.6.11
MEDIUM 5.3
CVE-2023-3869
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi…
Wpdiscuz
after 7.6.3
MEDIUM 5.3
CVE-2023-3998
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in…
Wpdiscuz
after 7.6.3
MEDIUM 6.1
CVE-2023-2309
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripti…
Wpforo Forum
2.1.9+
HIGH 8.8
CVE-2023-2249EPSS 61%
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, a…
Wpforo Forum
after 2.1.7
HIGH 8.8
CVE-2022-43492
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
Wpdiscuz
Mitigation only
HIGH 8.8
CVE-2022-40200
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Wpforo Forum
after 2.0.9
HIGH 8.8
CVE-2022-40192
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Wpforo Forum
after 2.0.9
MEDIUM 5.4
CVE-2022-40632
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
Wpforo Forum
after 2.0.5
HIGH 8.8
CVE-2022-38144
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.
Wpforo Forum
after 2.0.5
HIGH 7.5
CVE-2022-23984
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).
Wpdiscuz
after 7.3.11
MEDIUM 6.1
CVE-2021-24406
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect…
Wpforo Forum
1.9.7+
CRITICAL 10.0
CVE-2020-24186EPSS 95%
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to u…
Wpdiscuz
after 7.0.4
CRITICAL 9.8
CVE-2020-13640EPSS 13%
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via t…
Wpdiscuz
after 5.3.5
HIGH 8.8
CVE-2019-19109
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
Wpforo
No fix yet
MEDIUM 6.1
CVE-2019-19111
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.
Wpforo
No fix yet
MEDIUM 6.1
CVE-2019-19112
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
Wpforo
No fix yet
CRITICAL 9.8
CVE-2018-16613
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privileg…
Wpforo Forum
1.5.2+
MEDIUM 6.1
CVE-2018-11709
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Si…
Wpforo Forum
1.4.12+
CRITICAL 9.8
CVE-2018-11515
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
Wpforo
1.4.5+