Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Podlove Podcast Publisher HIGH 7.2
CVE-2024-52393

Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects …

Fix: after 4.1.15
Fix from $1,950 2024-11-14
Podlove Podcast Publisher HIGH 8.8
CVE-2024-43984

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publish…

Fix: 4.1.14+
Fix from $1,950 2024-10-31
Podlove Podcast Publisher MEDIUM 5.4
CVE-2024-43983

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows…

Fix: 4.1.14+
Fix from $1,600 2024-09-18
Podlove Podcast Publisher HIGH 8.8
CVE-2024-32143

Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0.

Fix: 4.1.1+
Fix from $1,950 2024-06-11
Podlove Podcast Publisher MEDIUM 5.4
CVE-2024-32812

Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through …

Fix: 4.0.12+
Fix from $1,600 2024-04-24
Podlove Podcast Publisher HIGH 8.8
CVE-2024-32139

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue af…

Fix: after 4.0.12
Fix from $1,950 2024-04-15
Podlove Podcast Publisher MEDIUM 6.1
CVE-2024-29915

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflec…

Fix: 4.0.10+
Fix from $1,600 2024-03-27
Podlove Subscribe Button HIGH 8.8
CVE-2024-1118

The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-butt…

Fix: after 1.3.10
Fix from $1,950 2024-02-07
Podlove Podcast Publisher MEDIUM 5.3
CVE-2024-1110

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init()…

Fix: after 4.0.11
Fix from $1,600 2024-02-07
Podlove Podcast Publisher MEDIUM 5.3
CVE-2024-1109

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_downloa…

Fix: after 4.0.11
Fix from $1,600 2024-02-07
Podlove Podcast Publisher HIGH 8.8
CVE-2023-25472

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions.

Fix: 3.8.4+
Fix from $1,950 2023-05-23
Podlove Subscribe Button HIGH 8.8
CVE-2023-25481

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.

Fix: 1.3.9+
Fix from $1,950 2023-05-23
Podlove Podcast Publisher CRITICAL 9.8
CVE-2021-24666EPSS 9%

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest ro…

Fix: 3.5.6+
Fix from $2,300 2021-09-27
Podlove Podcast Publisher CRITICAL 9.8
CVE-2016-10942

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.

Fix: 2.3.16+
Fix from $2,300 2019-09-13
Podlove Podcast Publisher MEDIUM 6.1
CVE-2016-10941

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.

Fix: 2.3.16+
Fix from $1,600 2019-09-13
Podlove Podcast Publisher HIGH 8.8
CVE-2017-12949

lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the …

Mitigation only
Fix from $1,950 2017-08-18