Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2024-12276
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Ultimate Member
2.10.0+
MEDIUM 5.3
CVE-2025-0318
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Ultimate Member
2.9.2+
HIGH 7.5
CVE-2025-0308
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Ultimate Member
2.9.2+
CRITICAL 9.8
CVE-2024-54367
Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a throu…
Forumwp
2.1.1+
HIGH 8.8
CVE-2023-23715
Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Con…
Jobboardwp
after 1.2.2
MEDIUM 6.1
CVE-2024-10879
The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_…
Forumwp
2.1.3+
MEDIUM 6.1
CVE-2024-11204
The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions u…
Forumwp
2.1.3+
MEDIUM 6.1
CVE-2024-10880
The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_…
Jobboardwp
1.3.1+
MEDIUM 5.4
CVE-2024-8519
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Ultimate Member
2.8.7+
HIGH 8.8
CVE-2024-8428
The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all …
Forumwp
after 2.0.2
MEDIUM 5.4
CVE-2024-2765
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Ultimate Member
2.8.5+
CRITICAL 9.8
CVE-2024-1071EPSS 89%
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Ultimate Member
2.8.3+
MEDIUM 6.1
CVE-2024-2123EPSS 27%
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…
Ultimate Member
2.8.4+
HIGH 8.8
CVE-2023-31216
Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.
Ultimate Member
after 2.6.0
CRITICAL 9.8
CVE-2023-3460EPSS 72%
The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allo…
Ultimate Member
2.6.7+
HIGH 7.5
CVE-2022-4061
The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthentic…
Jobboardwp
1.2.2+
HIGH 7.2
CVE-2022-3384
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_opt…
Ultimate Member
after 2.5.0
HIGH 7.2
CVE-2022-3383
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from…
Ultimate Member
after 2.5.0
HIGH 7.5
CVE-2022-3966
A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_templat…
Ultimate Member
2.5.1+
MEDIUM 5.4
CVE-2022-1208
The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured on individual user profile pag…
Ultimate Member
after 2.3.2
MEDIUM 5.4
CVE-2022-1209
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of…
Ultimate Member
after 2.3.1
MEDIUM 5.4
CVE-2021-24306
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate o…
Ultimate Member
2.1.20+
MEDIUM 5.3
CVE-2020-36170
The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.
Ultimate Member
2.1.13+
CRITICAL 9.8
CVE-2020-36155EPSS 9%
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacke…
Ultimate Member
2.1.12+
CRITICAL 9.8
CVE-2020-36157
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to th…
Ultimate Member
2.1.12+
HIGH 8.8
CVE-2020-36156
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any use…
Ultimate Member
2.1.12+
MEDIUM 5.3
CVE-2020-6859
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress …
Ultimate Member
after 2.1.2
MEDIUM 5.4
CVE-2019-14945
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
Ultimate Member
2.0.54+
MEDIUM 5.4
CVE-2019-14946
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
Ultimate Member
2.0.52+
MEDIUM 5.4
CVE-2019-14947
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
Ultimate Member
2.0.52+