Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Armember MEDIUM 5.4
CVE-2024-27995

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARMember – Membership Plugin…

Fix: 4.0.24+
Fix from $1,600 2024-03-21
Armember MEDIUM 5.3
CVE-2024-0969

The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This…

Fix: after 4.0.24
Fix from $1,600 2024-02-05
Arforms Form Builder MEDIUM 6.1
CVE-2023-6828

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Fix: after 1.5.8
Fix from $1,600 2024-01-11
Armember CRITICAL 9.8
CVE-2023-52200

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restri…

Fix: after 4.0.22
Fix from $2,300 2024-01-08
Bookingpress HIGH 8.8
CVE-2023-50841

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems BookingPress – Appointment B…

Fix: after 1.0.72
Fix from $1,950 2023-12-28
Bookingpress MEDIUM 5.3
CVE-2023-36507

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Repute Infosystems BookingPress – Appointment Booking Calendar Plugin and…

Fix: after 1.0.64
Fix from $1,600 2023-11-30
Bookingpress HIGH 7.2
CVE-2023-6219

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'bookingpress_process_upload…

Fix: after 1.0.76
Fix from $1,950 2023-11-28
Armember CRITICAL 9.8
CVE-2022-46808

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems ARMember armember-membership…

Fix: 4.0+
Fix from $2,300 2023-11-03
Armember MEDIUM 6.1
CVE-2022-47140

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember plugin <= 4.0.1 versions.

Fix: after 4.0.1
Fix from $1,600 2023-06-12
Arforms Form Builder MEDIUM 6.1
CVE-2022-45838

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions.

Fix: after 1.5.5
Fix from $1,600 2023-04-18
Bookingpress MEDIUM 5.3
CVE-2022-4340

The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowin…

Fix: 1.0.31+
Fix from $1,600 2023-01-02
Pricing Table CRITICAL 9.8
CVE-2022-0867EPSS 13%

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an S…

Fix: 3.6.1+
Fix from $2,300 2022-05-16
Bookingpress CRITICAL 9.8
CVE-2022-0739EPSS 37%

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL…

Fix: 1.0.11+
Fix from $2,300 2022-03-21
Arforms HIGH 7.5
CVE-2019-16902EPSS 10%

In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying …

Mitigation only
Fix from $1,950 2019-09-27
Arprice Lite MEDIUM 6.5
CVE-2019-14679

core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.

No fix yet
Fix from $1,600 2019-08-08
Repute Arforms HIGH 7.5
CVE-2018-15818

An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web server privileges by sending…

Fix: after 3.5.1
Fix from $1,950 2019-03-21