Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ninja Tables HIGH 7.2
CVE-2025-2940

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.…

Fix: 5.0.19+
Fix from $1,950 2025-06-27
Ninja Tables MEDIUM 5.6
CVE-2025-2939

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 vi…

Fix: 5.0.19+
Fix from $1,600 2025-06-03
Fluent Support HIGH 7.5
CVE-2024-13568

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u…

Fix: 1.8.6+
Fix from $1,950 2025-03-01
Ninja Tables MEDIUM 5.4
CVE-2024-12772

The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV,…

Fix: 5.0.17+
Fix from $1,600 2025-01-31
Fluent Support CRITICAL 9.8
CVE-2024-47302

Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security…

Fix: 1.8.1+
Fix from $2,300 2024-11-01
Fluent Support HIGH 8.5
CVE-2024-47304

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support a…

Fix: 1.8.1+
Fix from $1,950 2024-10-17
Ninja Tables MEDIUM 5.4
CVE-2024-7304

The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions …

Fix: 5.0.13+
Fix from $1,600 2024-08-27
Ninja Tables MEDIUM 5.3
CVE-2024-23504

Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5.

Fix: 5.0.6+
Fix from $1,600 2024-06-14
Pdf Generator For Fluent Forms MEDIUM 5.4
CVE-2023-6953

The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header, PDF bo…

Fix: 1.1.8+
Fix from $1,600 2024-02-05
Fluent Support HIGH 7.2
CVE-2023-51547

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support – WordPress He…

Fix: after 1.7.6
Fix from $1,950 2023-12-31
Fluentsmtp MEDIUM 6.1
CVE-2023-3087

The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.2.4 due to …

Fix: 2.2.5+
Fix from $1,600 2023-07-12
Fluentcrm MEDIUM 6.5
CVE-2023-1430

The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and in…

Fix: after 2.7.40
Fix from $1,600 2023-06-09
Ninja Tables HIGH 8.8
CVE-2022-47136

Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions.

Fix: after 4.3.4
Fix from $1,950 2023-05-25
Fluentsmtp MEDIUM 5.4
CVE-2023-0219

The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (…

Fix: 2.2.3+
Fix from $1,600 2023-03-13
Fluentauth HIGH 7.5
CVE-2022-4746

The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes…

Fix: 1.0.2+
Fix from $1,950 2023-01-23
Fluent Support HIGH 7.2
CVE-2022-2559

The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL state…

Fix: 1.5.8+
Fix from $1,950 2022-08-29
Ninja Job Board HIGH 7.5
CVE-2022-2544

The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenti…

Fix: 1.3.3+
Fix from $1,950 2022-08-22
Fluentsmtp MEDIUM 5.4
CVE-2021-24528

The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the…

Fix: 2.0.1+
Fix from $1,600 2021-08-30