Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-3714 The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler… Profilegrid 5.5.3+ Fix from $1,9502023-07-18 HIGH 8.8 CVE-2022-38062 Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Theme plugin <= 1.0.9 versions. Download Theme after 1.0.9 Fix from $1,9502023-07-17 MEDIUM 6.1 CVE-2023-35884 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions. Eventprime after 3.0.5 Fix from $1,6002023-06-20 HIGH 8.8 CVE-2022-36345 Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions. Download Plugin 2.0.5+ Fix from $1,9502023-05-28 MEDIUM 6.1 CVE-2023-33326 Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions. Eventprime 3.0.0+ Fix from $1,6002023-05-28 CRITICAL 9.8 CVE-2023-2499 The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insuffici… Registrationmagic after 5.2.1.0 Fix from $2,3002023-05-16 HIGH 7.2 CVE-2023-2548 The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due … Registrationmagic after 5.2.0.5 Fix from $1,9502023-05-16 MEDIUM 6.5 CVE-2023-0889 Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the option… Themeflection Numbers 2.0.1+ Fix from $1,6002023-04-17 HIGH 8.8 CVE-2023-0940 The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. Th… Profilegrid 5.3.1+ Fix from $1,9502023-03-20 HIGH 8.8 CVE-2023-25991 Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions. Registrationmagic 5.1.9.3+ Fix from $1,9502023-03-13 HIGH 8.8 CVE-2022-41791 Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress. Profilegrid after 5.1.6 Fix from $1,9502022-11-17 MEDIUM 6.1 CVE-2022-3578 The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected … Profilegrid 5.1.1+ Fix from $1,6002022-11-14 HIGH 7.2 CVE-2022-0420 The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the… Registrationmagic 5.0.2.2+ Fix from $1,9502022-03-07 MEDIUM 6.1 CVE-2021-24648 The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribu… Registrationmagic 5.0.1.9+ Fix from $1,6002022-02-01 MEDIUM 5.4 CVE-2022-0233 The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficien… Profilegrid after 4.7.4 Fix from $1,6002022-01-18 HIGH 7.2 CVE-2021-24862EPSS 73% The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statemen… Registrationmagic 5.0.1.6+ Fix from $1,9502022-01-10 HIGH 8.1 CVE-2021-4073EPSS 7% The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew … Registrationmagic after 5.0.1.7 Fix from $1,9502021-12-14 MEDIUM 5.7 CVE-2021-24703 The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any aut… Download Plugin 1.6.1+ Fix from $1,6002021-11-23 HIGH 8.1 CVE-2020-8435 An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id param… Registrationmagic No fix yet Fix from $1,9502020-03-12 MEDIUM 6.1 CVE-2020-8436 XSS was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress via the rm_form_id, rm_tr, or form_name parameter. Registrationmagic No fix yet Fix from $1,6002020-03-12 HIGH 8.8 CVE-2020-9454 A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site admi… Registrationmagic after 4.6.0.3 Fix from $1,9502020-03-06 HIGH 8.8 CVE-2020-9456 In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to ele… Registrationmagic after 4.6.0.3 Fix from $1,9502020-03-06 HIGH 8.8 CVE-2020-9457 The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable fo… Registrationmagic after 4.6.0.3 Fix from $1,9502020-03-06 HIGH 8.8 CVE-2020-9458 In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to exp… Registrationmagic after 4.6.0.3 Fix from $1,9502020-03-06 HIGH 8.8 CVE-2019-15873 The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php reque… Profilegrid 2.8.6+ Fix from $1,9502019-09-03