Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-43331
Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.
Wp Sms
6.9.4+
HIGH 8.8
CVE-2024-30454
Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.
Wp Sms
6.6.3+
MEDIUM 5.4
CVE-2024-25920
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue …
Wp Sms
6.4+
MEDIUM 6.1
CVE-2024-24881
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notificatio…
Wp Sms
6.5.3+
HIGH 7.5
CVE-2023-27447
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommer…
Wp Sms
6.0.4.1+
MEDIUM 6.1
CVE-2023-32742
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in VeronaLabs WP SMS plugin <= 6.1.4 versions.
Wp Sms
after 6.1.4
HIGH 8.8
CVE-2023-0955
The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. B…
Wp Statistics
14.0+
HIGH 8.8
CVE-2022-38074
SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.
Wp Statistics
13.2.11+
MEDIUM 6.5
CVE-2021-4333
The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing o…
Wp Statistics
after 13.1.1
HIGH 8.8
CVE-2022-4230EPSS 36%
The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks.…
Wp Statistics
13.2.9+
MEDIUM 6.1
CVE-2022-27231
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiti…
Wp Statistics
13.2.0+
MEDIUM 6.1
CVE-2022-1005
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading …
Wp Statistics
13.2.2+
CRITICAL 9.8
CVE-2022-25148EPSS 81%
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter …
Wp Statistics
after 13.1.5
HIGH 7.5
CVE-2022-25149EPSS 78%
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the …
Wp Statistics
after 13.1.5
MEDIUM 6.1
CVE-2022-25305EPSS 79%
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in t…
Wp Statistics
after 13.1.5
MEDIUM 6.1
CVE-2022-25306
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found…
Wp Statistics
after 13.1.5
MEDIUM 6.1
CVE-2022-25307
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter foun…
Wp Statistics
after 13.1.5
HIGH 7.5
CVE-2022-0651EPSS 32%
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type paramete…
Wp Statistics
after 13.1.5
HIGH 7.5
CVE-2022-0513EPSS 53%
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter…
Wp Statistics
after 13.1.4
MEDIUM 5.4
CVE-2021-24561
The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to …
Wp Sms
5.4.13+
HIGH 7.5
CVE-2021-24340EPSS 30%
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not firs…
Wp Statistics
13.0.8+
CRITICAL 9.8
CVE-2017-18515
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
Wp Statistics
12.0.8+
CRITICAL 9.8
CVE-2019-13275
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use…
Wp Statistics
after 12.6.6
MEDIUM 5.4
CVE-2019-12566
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with th…
Wp Statistics
after 12.6.5
MEDIUM 6.1
CVE-2019-10864
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer head…
Wp Statistics
after 12.6.2
MEDIUM 6.1
CVE-2018-1000556
WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An…
Wp Statistics
12.0.6+