Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2023-2655 The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading… Contact Form Maker after 1.13.23 Fix from $1,9502024-01-16 MEDIUM 5.4 CVE-2023-5048 The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder' shortcode in versions up to… Wp Form Builder after 1.0.72 Fix from $1,6002023-11-22 HIGH 8.8 CVE-2023-46619 Cross-Site Request Forgery (CSRF) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions. Wdsocialwidgets after 1.0.15 Fix from $1,9502023-11-13 MEDIUM 6.5 CVE-2023-5709 The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to in… Wd Widgettwitter after 1.0.9 Fix from $1,6002023-11-07 MEDIUM 6.1 CVE-2023-46090 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions. Wdsocialwidgets after 1.0.15 Fix from $1,6002023-10-26 MEDIUM 6.1 CVE-2023-45632 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <= 1.5.22 versions. Spidervplayer after 1.5.22 Fix from $1,6002023-10-18 HIGH 7.2 CVE-2021-24625 The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before u… Spidercatalog after 1.7.3 Fix from $1,9502021-11-08 HIGH 8.8 CVE-2019-11591 The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file… Contact Form 1.13.5+ Fix from $1,9502019-04-29 HIGH 8.8 CVE-2019-11557 The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant lo… Wp Form Builder 1.0.69+ Fix from $1,9502019-04-26 MEDIUM 5.4 CVE-2018-16164 Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web scri… Event Calendar Wd after 1.1.21 Fix from $1,6002019-01-09 HIGH 7.8 CVE-2018-10504 The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. Form Maker 1.12.24+ Fix from $1,9502018-04-27 MEDIUM 6.1 CVE-2018-10300 Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbi… Wd Instagram Feed 1.3.1+ Fix from $1,6002018-04-23 MEDIUM 6.1 CVE-2018-10301 Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inj… Wd Instagram Feed 1.3.1+ Fix from $1,6002018-04-23 CRITICAL 9.8 CVE-2018-5981 SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. Gallery Wd No fix yet Fix from $2,3002018-02-17 CRITICAL 9.8 CVE-2018-5991 SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerabil… Form Maker No fix yet Fix from $2,3002018-02-17 CRITICAL 9.8 CVE-2015-2798 SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parame… Contact Form Maker No fix yet Fix from $2,3002017-07-25 MEDIUM 6.1 CVE-2017-2224 Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via un… Event Calendar Wd after 1.0.93 Fix from $1,6002017-07-07 CRITICAL 9.8 CVE-2017-7719 SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter … Spider Event Calendar after 1.5.51 Fix from $2,3002017-04-12 MEDIUM 5.8 CVE-2015-4352 Cross-site request forgery (CSRF) vulnerability in the Spider Video Player module for Drupal allows remote attackers to hijack the authentication of … Web Dorado Spider Video Player Mitigation only Fix from $1,6002015-06-15 MEDIUM 6.8 CVE-2015-4350 Multiple cross-site request forgery (CSRF) vulnerabilities in the Spider Catalog module for Drupal allow remote attackers to hijack the authenticatio… Spider Catalog Mitigation only Fix from $1,6002015-06-15 HIGH 7.5 CVE-2015-2562EPSS 39% Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute… Ecommerce Wd No fix yet Fix from $1,9502015-03-20 HIGH 7.5 CVE-2015-2196EPSS 11% SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id par… Spider Calendar No fix yet Fix from $1,9502015-03-03