Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2025-5236
The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to,…
Chat For Telegram
1.2+
HIGH 7.2
CVE-2025-26977
Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Contro…
Filebird
6.4.6+
HIGH 8.8
CVE-2025-24591
Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access …
Gdpr Ccpa Compliance \& Cookie Consent Banner
2.7.2+
MEDIUM 6.5
CVE-2023-25966
Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…
Filebird
5.1.5+
HIGH 7.2
CVE-2024-53825
Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…
Filebird
after 6.3.2
HIGH 8.8
CVE-2024-8066
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function …
Filester
1.8.7+
HIGH 7.2
CVE-2024-9669
The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via…
Filester
1.8.6+
MEDIUM 5.4
CVE-2024-10055
The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_s…
Click To Chat
2.3.4+
MEDIUM 5.4
CVE-2024-49281
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All…
Click To Chat
2.3.4+
CRITICAL 9.8
CVE-2024-47331
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi Step for Contact Form cf7-mult…
Multi Step For Contact Form 7
2.7.8+
HIGH 8.8
CVE-2024-7031
The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt…
Filester
1.8.3+
MEDIUM 5.4
CVE-2024-5607
The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …
Gdpr Ccpa Compliance \& Cookie Consent Banner
2.7.1+
HIGH 7.5
CVE-2024-35166
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.
Filebird
5.6.4+
MEDIUM 5.4
CVE-2024-2345
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name p…
Filebird
5.6.4+
MEDIUM 5.4
CVE-2024-2346
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …
Filebird
5.6.4+
MEDIUM 5.4
CVE-2024-2837
The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin…
Wp Chat App
3.6.4+
MEDIUM 5.4
CVE-2024-2513
The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in all versions up to, and inclu…
Wp Chat App
3.6.3+
MEDIUM 5.4
CVE-2024-1761
The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including,…
Wp Chat App
after 3.6.1
MEDIUM 5.3
CVE-2023-6592
The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.
Fastdup
2.2+
HIGH 7.5
CVE-2023-51406
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue …
Fastdup
after 2.1.7
MEDIUM 5.4
CVE-2023-5740
The Live Chat with Facebook Messenger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'messenger' shortcode in all…
Live Chat With Facebook Messenger
after 1.0
HIGH 7.2
CVE-2023-4861
The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be…
Filester
1.8.1+
HIGH 8.8
CVE-2023-4827EPSS 7%
The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to m…
Filester
1.8+
CRITICAL 9.8
CVE-2020-36718
The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization…
Gpdr Ccpa Compliance Support
after 2.3
CRITICAL 9.8
CVE-2021-24385
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post requ…
Filebird
No fix yet
CRITICAL 9.8
CVE-2020-24142
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted request…
Video Downloader For Tiktok
Mitigation only
HIGH 7.5
CVE-2020-24143
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are…
Video Downloader For Tiktok
Mitigation only