Vulnerability index

Browse CVEs

60 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Popup Box MEDIUM 5.4
CVE-2025-15611

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allow…

Fix: 5.5.0+
Fix from $1,600 2026-04-07
Quiz Maker HIGH 7.5
CVE-2025-12426

The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to th…

Fix: 6.7.0.81+
Fix from $1,950 2025-11-19
Quiz Maker HIGH 7.5
CVE-2025-58015

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-maker allows Retrieve Embedded Se…

Fix: after 6.7.0.61
Fix from $1,950 2025-09-22
Quiz Maker HIGH 7.5
CVE-2025-10042

The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insuf…

Fix: 6.7.0.57+
Fix from $1,950 2025-09-17
Popup Box MEDIUM 5.4
CVE-2024-9599

The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Fix: 4.7.8+
Fix from $1,600 2025-05-15
Poll Maker HIGH 8.1
CVE-2025-47545

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker poll-maker allows Lev…

Fix: after 5.7.7
Fix from $1,950 2025-05-07
Poll Maker CRITICAL 9.8
CVE-2025-24577

Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Fix: 5.5.1+
Fix from $2,300 2025-04-17
Survey Maker MEDIUM 5.3
CVE-2025-32275

Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker survey-maker allows Identity Spoofing.This issue affects Survey Maker: from n…

Fix: after 5.1.5.4
Fix from $1,600 2025-04-10
Quiz Maker CRITICAL 9.8
CVE-2025-30774

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Inject…

Fix: 6.6.8.8+
Fix from $2,300 2025-04-01
Poll Maker CRITICAL 9.8
CVE-2025-26971

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker poll-maker allows Blind SQL …

Fix: 5.6.6+
Fix from $2,300 2025-02-25
Quiz Maker HIGH 7.5
CVE-2024-10628

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and…

Fix: 8.8.0.100 / 21.8.0.100+
Fix from $1,950 2025-01-26
Poll Maker MEDIUM 5.3
CVE-2024-56277

Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: from n/a through < 5.5.5.

Fix: 5.5.5+
Fix from $1,600 2025-01-21
Poll Maker MEDIUM 6.5
CVE-2024-56295

Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Fix: 5.5.7+
Fix from $1,600 2025-01-15
Poll Maker MEDIUM 5.3
CVE-2023-45766

Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Fix: 4.7.2+
Fix from $1,600 2025-01-02
Survey Maker CRITICAL 9.8
CVE-2023-22697

Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This is…

Fix: 3.2.1+
Fix from $2,300 2024-12-13
Poll Maker MEDIUM 5.3
CVE-2023-50904

Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Fix: 4.8.1+
Fix from $1,600 2024-12-09
Chartify CRITICAL 9.8
CVE-2024-10571

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the …

Fix: 2.9.6+
Fix from $2,300 2024-11-14
Poll Maker HIGH 7.2
CVE-2024-9874

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ paramete…

Fix: 5.4.7+
Fix from $1,950 2024-11-09
Poll Maker HIGH 7.2
CVE-2024-9475

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in…

Fix: 5.4.7+
Fix from $1,950 2024-10-26
Chatgpt Assistant HIGH 7.5
CVE-2024-7714

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated u…

Fix: 2.1.0+
Fix from $1,950 2024-09-27
Chatgpt Assistant HIGH 7.5
CVE-2024-7713

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users …

Fix: 2.1.0+
Fix from $1,950 2024-09-27
Photo Gallery MEDIUM 5.5
CVE-2024-37442

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery …

Fix: 5.7.1+
Fix from $1,600 2024-07-09
Quiz Maker CRITICAL 9.8
CVE-2024-6028EPSS 12%

The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including,…

Fix: 6.5.8.4+
Fix from $2,300 2024-06-25
Poll Maker MEDIUM 5.3
CVE-2024-3601

The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th…

Fix: 5.1.9+
Fix from $1,600 2024-05-02
Quiz Maker MEDIUM 5.3
CVE-2023-23985

Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4.

Fix: 6.3.9.5+
Fix from $1,600 2024-04-24
Poll Maker MEDIUM 6.1
CVE-2024-3600

The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on th…

Fix: 5.1.9+
Fix from $1,600 2024-04-19
Survey Maker MEDIUM 5.3
CVE-2023-35764

Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address w…

Fix: 3.6.4+
Fix from $1,600 2024-04-03
Survey Maker MEDIUM 6.1
CVE-2023-34423

Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be exec…

Fix: 3.6.4+
Fix from $1,600 2024-04-03
Survey Maker MEDIUM 5.4
CVE-2024-29918

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected…

Fix: 4.0.7+
Fix from $1,600 2024-03-27
Quiz Maker MEDIUM 5.3
CVE-2024-1079

The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function…

Fix: 6.5.2.5+
Fix from $1,600 2024-02-07