Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2023-45631
Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Secur…
Gallery
after 2.0.3
MEDIUM 6.5
CVE-2024-10856
The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” short…
Booking Calendar
3.2.0+
HIGH 8.8
CVE-2023-24407
Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control …
Booking Calendar
3.2.4+
MEDIUM 5.4
CVE-2024-7355
The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in al…
Organization Chart
1.5.1+
MEDIUM 6.3
CVE-2024-37542
Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: f…
Gallery
after 2.0.3
HIGH 8.8
CVE-2024-35750
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Albu…
Gallery
after 2.0.3
CRITICAL 9.8
CVE-2023-24373
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden…
Booking Calendar
3.2.4+
MEDIUM 6.1
CVE-2024-30550
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Albu…
Gallery
after 2.0.3
MEDIUM 5.4
CVE-2024-31120
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Albu…
Gallery
after 2.0.3
CRITICAL 9.8
CVE-2022-47428
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking …
Booking Calendar
3.2.8+
MEDIUM 6.1
CVE-2023-46075
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Contact Form Builder, Contact Widget plugin <= 2.1.6 versions.
Contact Form Builder
after 2.1.6
MEDIUM 6.1
CVE-2023-45630
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.
Gallery
after 2.0.3
HIGH 8.8
CVE-2023-45629
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.
Gallery Image And Video Gallery With Thumbnails
after 2.0.3
HIGH 7.2
CVE-2023-0900
The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leadin…
Pricing Table Builder
after 1.1.6
MEDIUM 6.1
CVE-2022-47603
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.
Image And Video Gallery With Thumbnails
2.0.2+
MEDIUM 5.4
CVE-2022-47438
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions.
Booking Calendar
after 3.2.3
MEDIUM 5.4
CVE-2023-23983
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to theme deletion.
Responsive Vertical Icon Menu
1.5.9+
HIGH 8.8
CVE-2023-24384
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.
Organization Chart
after 1.4.4
MEDIUM 5.4
CVE-2023-24388
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin form…
Booking Calendar
3.2.4+
MEDIUM 5.4
CVE-2023-0177
The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputti…
Social Like Box And Page
0.8.41+
CRITICAL 9.8
CVE-2022-3982
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated us…
Booking Calendar
3.2.2+
MEDIUM 6.1
CVE-2022-1946
The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (avail…
Gallery
2.0.0+
MEDIUM 6.1
CVE-2022-0640
The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page,…
Pricing Table Builder
1.1.5+
MEDIUM 5.4
CVE-2021-24577
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting ad…
Coming Soon And Maintenance Mode
3.5.3+
HIGH 8.8
CVE-2021-34636
The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in…
Countdown And Countup\, Woocommerce Sales Timer
after 1.5.7
MEDIUM 5.4
CVE-2021-24464
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, a…
Youtube Embed\, Playlist And Popup
2.3.9+
CRITICAL 9.8
CVE-2021-24442EPSS 46%
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST paramete…
Poll\, Survey\, Questionnaire And Voting System
1.5.3+
HIGH 7.5
CVE-2018-10363
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote a…
Booking Calendar
Mitigation only
CRITICAL 9.8
CVE-2017-14125
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL comman…
Responsive Image Gallery Gallery Album
after 1.2.0