Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Registrationmagic MEDIUM 6.5
CVE-2023-23989

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic.This issue affects …

Fix: 5.1.9.3+
Fix from $1,600 2024-04-24
Profilegrid HIGH 8.8
CVE-2024-32808

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

Fix: 5.8.0+
Fix from $1,950 2024-04-24
Profilegrid HIGH 8.8
CVE-2024-32772

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

Fix: 5.8.0+
Fix from $1,950 2024-04-24
Registrationmagic HIGH 7.5
CVE-2023-23976

Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue…

Fix: 5.1.9.3+
Fix from $1,950 2024-04-24
Profilegrid HIGH 8.8
CVE-2024-31362

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

Fix: 5.7.9+
Fix from $1,950 2024-04-12
Registrationmagic CRITICAL 9.8
CVE-2024-25935

Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9.

Fix: 5.2.6.0+
Fix from $2,300 2024-04-11
Registrationmagic HIGH 8.8
CVE-2024-1990

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injecti…

Fix: 5.3.2.0+
Fix from $1,950 2024-04-09
Registrationmagic HIGH 8.8
CVE-2024-1991

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalat…

Fix: 5.3.1.0+
Fix from $1,950 2024-04-09
Profilegrid HIGH 7.1
CVE-2024-31291

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.

Fix: 5.7.7+
Fix from $1,950 2024-04-07
Profilegrid MEDIUM 6.5
CVE-2024-30513

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.

Fix: 5.7.3+
Fix from $1,600 2024-03-29
Profilegrid CRITICAL 9.8
CVE-2024-30490

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects Profil…

Fix: 5.7.9+
Fix from $2,300 2024-03-29
Profilegrid HIGH 8.8
CVE-2024-30491EPSS 32%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects Profil…

Fix: 5.7.9+
Fix from $1,950 2024-03-29
Profilegrid HIGH 8.8
CVE-2024-30241

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects Profil…

Fix: 5.7.2+
Fix from $1,950 2024-03-28
Eventprime HIGH 7.5
CVE-2024-24832

Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

Fix: 3.4.0+
Fix from $1,950 2024-03-23
Registrationmagic MEDIUM 6.1
CVE-2024-29113

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XS…

Fix: 5.2.6.0+
Fix from $1,600 2024-03-19
Eventprime MEDIUM 5.3
CVE-2024-1321

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4…

Fix: 3.4.3+
Fix from $1,600 2024-03-13
Eventprime MEDIUM 6.1
CVE-2024-1320

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' par…

Fix: 3.4.4+
Fix from $1,600 2024-03-09
Eventprime MEDIUM 5.4
CVE-2024-1125

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ch…

Fix: 3.4.4+
Fix from $1,600 2024-03-09
Eventprime MEDIUM 6.5
CVE-2024-1123

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab…

Fix: 3.4.3+
Fix from $1,600 2024-03-09
Registrationmagic MEDIUM 6.1
CVE-2023-51509

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registrati…

Fix: after 5.2.4.1
Fix from $1,600 2024-02-01
Eventprime MEDIUM 5.3
CVE-2023-6447

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password…

Fix: 3.3.6+
Fix from $1,600 2024-01-22
Profilegrid HIGH 8.8
CVE-2022-36352

Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – …

Fix: after 5.0.3
Fix from $1,950 2024-01-08
Registrationmagic HIGH 7.2
CVE-2023-50846

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Re…

Fix: after 5.2.4.5
Fix from $1,950 2023-12-28
Registrationmagic HIGH 8.8
CVE-2023-47645

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and U…

Fix: 5.2.3.0+
Fix from $1,950 2023-11-30
Eventprime MEDIUM 5.3
CVE-2023-4252

The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings witho…

Fix: after 3.2.9
Fix from $1,600 2023-11-27
Profilegrid HIGH 8.8
CVE-2023-47644

Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects Pr…

Fix: after 5.6.6
Fix from $1,950 2023-11-18
Eventprime MEDIUM 6.1
CVE-2023-5238

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injec…

Fix: 3.2.0+
Fix from $1,600 2023-10-31
Eventprime MEDIUM 6.1
CVE-2023-4250

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Refle…

Fix: 3.2.0+
Fix from $1,600 2023-10-31
Eventprime MEDIUM 6.1
CVE-2023-45637

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions.

Fix: after 3.1.5
Fix from $1,600 2023-10-25
Profilegrid HIGH 8.8
CVE-2023-3713

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check…

Fix: after 5.5.1
Fix from $1,950 2023-07-18