Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ari Adminer HIGH 7.3
CVE-2019-25215

The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin i…

Fix: after 1.1.14
Fix from $1,950 2024-10-16
Ari Stream Quiz HIGH 8.8
CVE-2023-51487

Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft ARI Stream Quiz.This issue affects ARI Stream Quiz: from n/a through 1.2.32.

Fix: 1.3.0+
Fix from $1,950 2024-03-16
Contact Form 7 Connector HIGH 8.8
CVE-2024-24884

Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.…

Fix: after 1.2.2
Fix from $1,950 2024-02-12
Contact Form 7 Connector MEDIUM 6.1
CVE-2024-0239

The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to…

Fix: 1.2.3+
Fix from $1,600 2024-01-16
Ari Stream Quiz HIGH 8.8
CVE-2023-52182

Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPres…

Fix: after 1.3.0
Fix from $1,950 2023-12-31
Ari Stream Quiz MEDIUM 5.4
CVE-2023-47835

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Bu…

Fix: after 1.2.32
Fix from $1,600 2023-11-23
Ari Fancy Lightbox MEDIUM 6.1
CVE-2022-0161

The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leadi…

Fix: 1.3.9+
Fix from $1,600 2022-03-14
Ari Adminer MEDIUM 5.4
CVE-2020-19156

Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections'…

No fix yet
Fix from $1,600 2021-09-15