Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-23792 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Swatchly plugin <= 1.2.0 versions. Swatchly 1.2.1+ Fix from $1,9502023-07-11 HIGH 8.8 CVE-2023-23804 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions. Ht Feed 1.2.8+ Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-23802 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions. Ht Easy Ga4 \(google Analytics 4\) 1.0.7+ Fix from $1,9502023-06-15 HIGH 8.8 CVE-2023-23801 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions. Really Simple Google Tag Manager 1.0.7+ Fix from $1,9502023-04-06 MEDIUM 6.5 CVE-2023-0500 The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admi… Wp Film Studio 1.3.5+ Fix from $1,6002023-03-27 MEDIUM 6.5 CVE-2023-0501 The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins… Wp Insurance 2.1.4+ Fix from $1,6002023-03-27 MEDIUM 6.5 CVE-2023-0502 The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins act… Wp News after 1.1.9 Fix from $1,6002023-03-27 MEDIUM 5.4 CVE-2022-46798 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change. Woolentor Woocommerce Elementor Addons \+ Builder 2.5.2+ Fix from $1,6002023-03-01 CRITICAL 9.8 CVE-2023-0232 The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead t… Shoplentor 2.5.4+ Fix from $2,3002023-02-21 MEDIUM 5.4 CVE-2023-0231 The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where … Shoplentor 2.5.4+ Fix from $1,6002023-02-21 MEDIUM 5.4 CVE-2022-4650 The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as… Hashbar 1.3.6+ Fix from $1,6002023-01-23 MEDIUM 5.4 CVE-2021-24261 The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site… Ht Mega 1.5.7+ Fix from $1,6002021-05-05 MEDIUM 5.4 CVE-2021-24262 The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting… Woolentor Woocommerce Elementor Addons \+ Builder 1.8.6+ Fix from $1,6002021-05-05