Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-31474EPSS 64% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue … Backupbuddy 8.7.5.0+ Fix from $1,9502023-03-13 MEDIUM 6.1 CVE-2022-4897 The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to … Backupbuddy 8.8.3+ Fix from $1,6002023-02-21 HIGH 7.5 CVE-2020-36176 The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing acco… Ithemes Security 7.7.0+ Fix from $1,9502021-01-06 CRITICAL 9.8 CVE-2020-14092EPSS 95% The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection. Paypal Pro 1.1.65+ Fix from $2,3002020-07-02 MEDIUM 6.1 CVE-2015-9372 Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Membership 1.3.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9374 Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Stripe 1.2.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9375 Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Table Rate Shipping 1.1.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9376 iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg(). Mobile 1.2.8+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9377 iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg(). Builder Theme Depot 5.0.30+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9378 iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg(). Builder Theme Market 5.1.27+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9379 iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg(). Builder Style Manager 0.7.7+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9369 Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Easy Us Sales Taxes 1.1.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9370 Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Invoices 1.4.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9371 Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Manual Purchases 1.1.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9363 iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Exchange 1.12.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9365 Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Authorize.net 1.1.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9366 Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Custom Url Tracking 1.1.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9367 Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Easy Canadian Sales Taxes 1.1.0+ Fix from $1,6002019-08-28 MEDIUM 6.1 CVE-2015-9368 Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). Easy Eu Value Added \(vat\) Taxes 1.2.0+ Fix from $1,6002019-08-28 HIGH 7.2 CVE-2018-12636EPSS 30% The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs pa… Security 7.0.3+ Fix from $1,9502018-06-22 HIGH 7.5 CVE-2018-7433 The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page. Security after 6.9.0 Fix from $1,9502018-03-02 HIGH 7.5 CVE-2013-2741 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, whic… Backupbuddy No fix yet Fix from $1,9502013-04-02 HIGH 7.5 CVE-2013-2742 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a re… Backupbuddy No fix yet Fix from $1,9502013-04-02 HIGH 7.5 CVE-2013-2743 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via … Backupbuddy No fix yet Fix from $1,9502013-04-02 MEDIUM 5.0 CVE-2013-2744 importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo actio… Backupbuddy No fix yet Fix from $1,6002013-04-02