Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cooked HIGH 8.8
CVE-2024-49290

Cross-Site Request Forgery (CSRF) vulnerability in Gora Tech LLC Cooked Pro allows Cross Site Request Forgery.This issue affects Cooked Pro: from n/a…

Fix: 1.8.0+
Fix from $1,950 2024-10-20
Cooked MEDIUM 5.4
CVE-2024-41816

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-time…

Fix: 1.8.1+
Fix from $1,600 2024-08-05
Cooked MEDIUM 5.4
CVE-2024-39682

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 d…

Fix: 1.8.0+
Fix from $1,600 2024-07-18
Cooked HIGH 8.8
CVE-2024-39678

Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.1…

Fix: 1.8.0+
Fix from $1,950 2024-07-18
Cooked HIGH 8.8
CVE-2024-39679

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in…

Fix: 1.8.0+
Fix from $1,950 2024-07-18
Cooked HIGH 8.8
CVE-2024-39680

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in…

Fix: 1.8.0+
Fix from $1,950 2024-07-18
Cooked HIGH 8.8
CVE-2024-39681

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and in…

Fix: 1.8.0+
Fix from $1,950 2024-07-18
Cooked MEDIUM 5.4
CVE-2024-37308

The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in…

Fix: 1.8.0+
Fix from $1,600 2024-06-13
Booked HIGH 7.5
CVE-2022-36399

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This is…

Fix: 2.4.4+
Fix from $1,950 2023-12-28
Cooked MEDIUM 5.4
CVE-2023-44477

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions.

Fix: after 1.7.13
Fix from $1,600 2023-10-02
Cooked CRITICAL 9.8
CVE-2022-3900EPSS 19%

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked…

Fix: 1.7.5.7+
Fix from $2,300 2022-12-12
Cooked MEDIUM 6.1
CVE-2021-24233

The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of…

Fix: 1.7.5.6+
Fix from $1,600 2021-04-22