Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Custom Field Template MEDIUM 5.4
CVE-2024-44062

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template …

Fix: 2.6.6+
Fix from $1,600 2024-09-15
Custom Field Template MEDIUM 5.4
CVE-2023-6745

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' shortcode in all versions up to, a…

Fix: 2.6.2+
Fix from $1,600 2024-06-11
Custom Field Template MEDIUM 5.4
CVE-2024-0627

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom field name column in all versions…

Fix: 2.6.2+
Fix from $1,600 2024-06-11
Custom Post Type Page Template HIGH 8.8
CVE-2023-50372

Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Post Type Page Template.This issue affects Custom Post Type Page Template…

Fix: after 1.1
Fix from $1,950 2023-12-18
Custom Field Template MEDIUM 6.1
CVE-2023-38392

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.9 versions.

Fix: 2.6.0+
Fix from $1,600 2023-08-07
Custom Field Template HIGH 8.8
CVE-2023-22695

Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions.

Fix: 2.5.9+
Fix from $1,950 2023-07-10
Lightbox Gallery MEDIUM 5.4
CVE-2022-4682

The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before outputting them back in a pag…

Fix: 0.9.5+
Fix from $1,600 2023-02-13
Custom Field Template HIGH 7.2
CVE-2022-4324EPSS 18%

The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issue…

Fix: 2.5.8+
Fix from $1,950 2023-01-02