Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Himer HIGH 8.1
CVE-2024-2232

The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

Fix: 2.1.3+
Fix from $1,950 2024-08-05
Wpqa Builder HIGH 8.8
CVE-2024-2376

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Fix: 6.1.1+
Fix from $1,950 2024-07-03
Himer MEDIUM 6.5
CVE-2024-2231

The allows any authenticated user to join a private group due to a missing authorization check on a function

Fix: 2.1.1+
Fix from $1,600 2024-07-03
Himer MEDIUM 5.4
CVE-2024-2234

The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contrib…

Fix: 2.1.1+
Fix from $1,600 2024-07-03
Wpqa Builder MEDIUM 5.4
CVE-2024-2375

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such …

Fix: 6.1.1+
Fix from $1,600 2024-07-03
Wpqa Builder HIGH 8.8
CVE-2022-3688

The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could allow attackers to make logge…

Fix: 5.9+
Fix from $1,950 2022-11-21
Discy MEDIUM 6.5
CVE-2022-1323

The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logge…

Fix: 5.0+
Fix from $1,600 2022-08-08
Discy MEDIUM 6.5
CVE-2022-1422

The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin in…

Fix: 5.2+
Fix from $1,600 2022-06-08
Ask Me MEDIUM 6.5
CVE-2022-1424

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to pe…

Fix: 6.8.2+
Fix from $1,600 2022-06-08
Ask Me MEDIUM 6.1
CVE-2022-1241

The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cr…

Fix: 6.8.2+
Fix from $1,600 2022-06-08
Wpqa Builder MEDIUM 6.1
CVE-2022-1597

The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset pas…

Fix: 5.4+
Fix from $1,600 2022-06-08
Wpqa Builder MEDIUM 5.3
CVE-2022-1598EPSS 5%

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unau…

Fix: 5.4+
Fix from $1,600 2022-06-08
Wpqa Builder MEDIUM 5.4
CVE-2022-1051

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phon…

Fix: 5.2+
Fix from $1,600 2022-05-16