Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2025-0897
The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode…
Modal Window
6.1.6+
HIGH 8.8
CVE-2025-24717
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal W…
Modal Window
6.1.5+
MEDIUM 5.4
CVE-2025-24715
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box counter-box allows Cross Site Request Forgery.This issue affects Counter B…
Counter Box
2.0.6+
CRITICAL 9.8
CVE-2024-6926
The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX actio…
Viral Signup
after 2.1
MEDIUM 5.4
CVE-2024-43346
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wow-Company Modal Window allows Stored X…
Modal Window
6.0.4+
CRITICAL 9.8
CVE-2024-35629
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Dow…
Easy Digital Downloads
after 1.0.2
MEDIUM 6.1
CVE-2024-3478
The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins …
Herd Effects
5.2.7+
MEDIUM 5.2
CVE-2024-3481
The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins p…
Counter Box
1.2.4+
HIGH 8.8
CVE-2024-3474
The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in adm…
Wow Skype Buttons
4.0.4+
HIGH 8.8
CVE-2024-3476
The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admin…
Side Menu Lite
4.2.1+
HIGH 7.5
CVE-2024-3475
The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admin…
Sticky Buttons
3.2.4+
MEDIUM 5.9
CVE-2024-3472
The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a l…
Modal Window
5.3.10+
MEDIUM 5.4
CVE-2024-2457
The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all v…
Modal Window
5.3.9+
HIGH 8.8
CVE-2023-52149
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.
Floating Button
after 6.0
HIGH 8.8
CVE-2023-49155
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily …
Button Generator
after 2.3.8
HIGH 8.8
CVE-2023-27418
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite – add sticky fixed buttons plugin <= 4.0 versions.
Side Menu Lite
after 4.0
MEDIUM 5.4
CVE-2023-5161
The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 5.3.5 due to insu…
Modal Window
after 5.3.5
MEDIUM 6.5
CVE-2023-25443
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.5 versions.
Button Generator
after 2.3.5
MEDIUM 6.1
CVE-2023-2362
The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator B…
Bubble Menu
1.2.2 / 1.5.1+
MEDIUM 5.4
CVE-2023-23984
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leading to form deletion.
Bubble Menu
3.0.2+
MEDIUM 6.5
CVE-2022-2388
The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to…
Wp Coder
2.5.3+
HIGH 8.8
CVE-2022-2245
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a …
Counter Box
1.2.1+
HIGH 7.2
CVE-2022-29447
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
Hover Effects
after 2.1
HIGH 7.2
CVE-2022-29446
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
Counter Box
after 1.1.1
HIGH 7.2
CVE-2021-25064
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an…
Wow Countdowns
after 3.1.2
HIGH 8.8
CVE-2021-25051
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well …
Modal Window
5.2.2+
HIGH 8.8
CVE-2021-25052
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as w…
Button Generator
2.3.3+
HIGH 8.8
CVE-2021-25053
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as w…
Wp Coder
2.5.2+
HIGH 8.8
CVE-2021-25054
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authentic…
Wpcalc
after 2.1
HIGH 7.2
CVE-2021-24628
The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a fo…
Wow Forms
after 3.1.3