Vulnerability index

Browse CVEs

58 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2025-60227 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pipes allows Path Traversal.Thi… Wp Pipes after 1.4.3 Fix from $1,9502025-10-22 MEDIUM 6.1 CVE-2025-28977 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS. This i… Wp Pipes after 1.4.3 Fix from $1,6002025-08-20 CRITICAL 9.8 CVE-2025-28979 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PH… Wp Pipes after 1.4.3 Fix from $2,3002025-08-14 CRITICAL 9.8 CVE-2025-28982 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This i… Wp Pipes after 1.4.3 Fix from $2,3002025-07-16 CRITICAL 9.1 CVE-2025-48267 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue … Wp Pipes 1.4.3+ Fix from $2,3002025-06-09 MEDIUM 6.5 CVE-2025-47664 Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a thro… Wp Pipes after 1.4.3 Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2024-13599 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5… Learnpress 4.2.7.5.1+ Fix from $1,6002025-01-25 MEDIUM 5.3 CVE-2024-12370 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in a… Wp Hotel Booking 2.1.6+ Fix from $1,6002025-01-17 MEDIUM 6.1 CVE-2024-12283 The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 … Wp Pipes 1.4.2+ Fix from $1,6002024-12-11 MEDIUM 5.3 CVE-2024-11868 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.… Learnpress 4.2.7.4+ Fix from $1,6002024-12-10 MEDIUM 6.1 CVE-2024-9609 The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learn… Learnpress Export Import 4.0.5+ Fix from $1,6002024-11-15 HIGH 8.8 CVE-2024-51582 Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel … Wp Hotel Booking after 2.1.4 Fix from $1,9502024-11-04 HIGH 8.8 CVE-2024-7855EPSS 18% The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function… Wp Hotel Booking 2.1.3+ Fix from $1,9502024-10-02 HIGH 7.5 CVE-2024-8522EPSS 63% The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpres… Learnpress 4.2.7.1+ Fix from $1,9502024-09-12 HIGH 7.5 CVE-2024-8529EPSS 12% The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/… Learnpress 4.2.7.1+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-7717 The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, … Wp Events Manager 2.2.0+ Fix from $1,9502024-08-31 HIGH 8.8 CVE-2024-39641 Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2. Learnpress 4.2.6.9+ Fix from $1,9502024-08-26 MEDIUM 6.5 CVE-2024-7548 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to,… Learnpress 4.2.6.9.4+ Fix from $1,6002024-08-08 HIGH 8.8 CVE-2024-6589 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via … Learnpress after 4.2.6.8.2 Fix from $1,9502024-07-25 MEDIUM 5.3 CVE-2024-6088 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the '… Learnpress 4.2.6.8.2+ Fix from $1,6002024-07-02 MEDIUM 5.3 CVE-2024-6099 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and includ… Learnpress 4.2.6.8.2+ Fix from $1,6002024-07-02 CRITICAL 9.8 CVE-2024-3605 The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API en… Wp Hotel Booking after 2.1.0 Fix from $2,3002024-06-20 HIGH 8.8 CVE-2023-36516 Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3. Learnpress 4.2.3.1+ Fix from $1,9502024-06-19 CRITICAL 9.8 CVE-2023-36515 Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3. Learnpress 4.2.3.1+ Fix from $2,3002024-06-19 MEDIUM 6.1 CVE-2024-35697 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThimPress Eduma allows Reflected XSS.Thi… Eduma 5.4.8+ Fix from $1,6002024-06-08 MEDIUM 5.3 CVE-2024-5483 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.… Learnpress 4.2.6.8.1+ Fix from $1,6002024-06-05 MEDIUM 5.4 CVE-2024-4971 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up … Learnpress 4.2.6.7+ Fix from $1,6002024-05-22 MEDIUM 6.5 CVE-2024-4444 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. Th… Learnpress 4.2.6.6+ Fix from $1,6002024-05-14 CRITICAL 9.8 CVE-2024-4434EPSS 37% The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, a… Learnpress 4.2.6.6+ Fix from $2,3002024-05-14 HIGH 8.8 CVE-2024-4397 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_p… Learnpress 4.2.6.6+ Fix from $1,9502024-05-14