Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-23989 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic.This issue affects … Registrationmagic 5.1.9.3+ Fix from $1,6002024-04-24 HIGH 8.8 CVE-2024-32808 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. Profilegrid 5.8.0+ Fix from $1,9502024-04-24 HIGH 8.8 CVE-2024-32772 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. Profilegrid 5.8.0+ Fix from $1,9502024-04-24 HIGH 7.5 CVE-2023-23976 Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue… Registrationmagic 5.1.9.3+ Fix from $1,9502024-04-24 HIGH 8.8 CVE-2024-31362 Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. Profilegrid 5.7.9+ Fix from $1,9502024-04-12 CRITICAL 9.8 CVE-2024-25935 Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9. Registrationmagic 5.2.6.0+ Fix from $2,3002024-04-11 HIGH 8.8 CVE-2024-1990 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injecti… Registrationmagic 5.3.2.0+ Fix from $1,9502024-04-09 HIGH 8.8 CVE-2024-1991 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalat… Registrationmagic 5.3.1.0+ Fix from $1,9502024-04-09 HIGH 7.1 CVE-2024-31291 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6. Profilegrid 5.7.7+ Fix from $1,9502024-04-07 MEDIUM 6.5 CVE-2024-30513 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2. Profilegrid 5.7.3+ Fix from $1,6002024-03-29 CRITICAL 9.8 CVE-2024-30490 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects Profil… Profilegrid 5.7.9+ Fix from $2,3002024-03-29 HIGH 8.8 CVE-2024-30491EPSS 32% Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects Profil… Profilegrid 5.7.9+ Fix from $1,9502024-03-29 HIGH 8.8 CVE-2024-30241 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects Profil… Profilegrid 5.7.2+ Fix from $1,9502024-03-28 HIGH 7.5 CVE-2024-24832 Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9. Eventprime 3.4.0+ Fix from $1,9502024-03-23 MEDIUM 6.1 CVE-2024-29113 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XS… Registrationmagic 5.2.6.0+ Fix from $1,6002024-03-19 MEDIUM 5.3 CVE-2024-1321 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4… Eventprime 3.4.3+ Fix from $1,6002024-03-13 MEDIUM 6.1 CVE-2024-1320 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' par… Eventprime 3.4.4+ Fix from $1,6002024-03-09 MEDIUM 5.4 CVE-2024-1125 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ch… Eventprime 3.4.4+ Fix from $1,6002024-03-09 MEDIUM 6.5 CVE-2024-1123 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… Eventprime 3.4.3+ Fix from $1,6002024-03-09 MEDIUM 6.1 CVE-2023-51509 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registrati… Registrationmagic after 5.2.4.1 Fix from $1,6002024-02-01 MEDIUM 5.3 CVE-2023-6447 The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password… Eventprime 3.3.6+ Fix from $1,6002024-01-22 HIGH 8.8 CVE-2022-36352 Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – … Profilegrid after 5.0.3 Fix from $1,9502024-01-08 HIGH 7.2 CVE-2023-50846 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Re… Registrationmagic after 5.2.4.5 Fix from $1,9502023-12-28 HIGH 8.8 CVE-2023-47645 Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and U… Registrationmagic 5.2.3.0+ Fix from $1,9502023-11-30 MEDIUM 5.3 CVE-2023-4252 The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings witho… Eventprime after 3.2.9 Fix from $1,6002023-11-27 HIGH 8.8 CVE-2023-47644 Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects Pr… Profilegrid after 5.6.6 Fix from $1,9502023-11-18 MEDIUM 6.1 CVE-2023-5238 The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injec… Eventprime 3.2.0+ Fix from $1,6002023-10-31 MEDIUM 6.1 CVE-2023-4250 The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Refle… Eventprime 3.2.0+ Fix from $1,6002023-10-31 MEDIUM 6.1 CVE-2023-45637 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tickets plugin <= 3.1.5 versions. Eventprime after 3.1.5 Fix from $1,6002023-10-25 HIGH 8.8 CVE-2023-3713 The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check… Profilegrid after 5.5.1 Fix from $1,9502023-07-18