Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cyan Backup MEDIUM 5.4
CVE-2024-9663

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin…

Fix: 2.5.3+
Fix from $1,600 2025-05-15
Cyan Backup MEDIUM 5.4
CVE-2024-9662

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin…

Fix: 2.5.3+
Fix from $1,600 2025-05-15
Auto Iframe MEDIUM 5.4
CVE-2024-10151

The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Fix: 2.0+
Fix from $1,600 2025-01-08
Sully HIGH 7.1
CVE-2024-5151

The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to pe…

Fix: 4.3.1+
Fix from $1,950 2024-07-13
Sully HIGH 8.8
CVE-2024-5034

The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwante…

Fix: 4.3.1+
Fix from $1,950 2024-07-13
Sully MEDIUM 5.9
CVE-2024-5033

The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow a…

Fix: 4.3.1+
Fix from $1,600 2024-07-13
Schedule Posts Calendar HIGH 8.8
CVE-2023-40556

Cross-Site Request Forgery (CSRF) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.

Fix: after 5.2
Fix from $1,950 2023-10-06