Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Contact Form Maker HIGH 7.2
CVE-2023-2655

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading…

Fix: after 1.13.23
Fix from $1,950 2024-01-16
Wp Form Builder MEDIUM 5.4
CVE-2023-5048

The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder' shortcode in versions up to…

Fix: after 1.0.72
Fix from $1,600 2023-11-22
Wdsocialwidgets HIGH 8.8
CVE-2023-46619

Cross-Site Request Forgery (CSRF) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions.

Fix: after 1.0.15
Fix from $1,950 2023-11-13
Wd Widgettwitter MEDIUM 6.5
CVE-2023-5709

The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to in…

Fix: after 1.0.9
Fix from $1,600 2023-11-07
Wdsocialwidgets MEDIUM 6.1
CVE-2023-46090

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions.

Fix: after 1.0.15
Fix from $1,600 2023-10-26
Spidervplayer MEDIUM 6.1
CVE-2023-45632

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <= 1.5.22 versions.

Fix: after 1.5.22
Fix from $1,600 2023-10-18
Spidercatalog HIGH 7.2
CVE-2021-24625

The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before u…

Fix: after 1.7.3
Fix from $1,950 2021-11-08
Contact Form HIGH 8.8
CVE-2019-11591

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file…

Fix: 1.13.5+
Fix from $1,950 2019-04-29
Wp Form Builder HIGH 8.8
CVE-2019-11557

The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant lo…

Fix: 1.0.69+
Fix from $1,950 2019-04-26
Event Calendar Wd MEDIUM 5.4
CVE-2018-16164

Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web scri…

Fix: after 1.1.21
Fix from $1,600 2019-01-09
Form Maker HIGH 7.8
CVE-2018-10504

The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.

Fix: 1.12.24+
Fix from $1,950 2018-04-27
Wd Instagram Feed MEDIUM 6.1
CVE-2018-10300

Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbi…

Fix: 1.3.1+
Fix from $1,600 2018-04-23
Wd Instagram Feed MEDIUM 6.1
CVE-2018-10301

Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inj…

Fix: 1.3.1+
Fix from $1,600 2018-04-23
Gallery Wd CRITICAL 9.8
CVE-2018-5981

SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.

No fix yet
Fix from $2,300 2018-02-17
Form Maker CRITICAL 9.8
CVE-2018-5991

SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerabil…

No fix yet
Fix from $2,300 2018-02-17
Contact Form Maker CRITICAL 9.8
CVE-2015-2798

SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parame…

No fix yet
Fix from $2,300 2017-07-25
Event Calendar Wd MEDIUM 6.1
CVE-2017-2224

Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via un…

Fix: after 1.0.93
Fix from $1,600 2017-07-07
Spider Event Calendar CRITICAL 9.8
CVE-2017-7719

SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter …

Fix: after 1.5.51
Fix from $2,300 2017-04-12
Web Dorado Spider Video Player MEDIUM 5.8
CVE-2015-4352

Cross-site request forgery (CSRF) vulnerability in the Spider Video Player module for Drupal allows remote attackers to hijack the authentication of …

Mitigation only
Fix from $1,600 2015-06-15
Spider Catalog MEDIUM 6.8
CVE-2015-4350

Multiple cross-site request forgery (CSRF) vulnerabilities in the Spider Catalog module for Drupal allow remote attackers to hijack the authenticatio…

Mitigation only
Fix from $1,600 2015-06-15
Ecommerce Wd HIGH 7.5
CVE-2015-2562EPSS 39%

Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute…

No fix yet
Fix from $1,950 2015-03-20
Spider Calendar HIGH 7.5
CVE-2015-2196EPSS 11%

SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id par…

No fix yet
Fix from $1,950 2015-03-03