Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Balkon MEDIUM 6.1
CVE-2023-36502

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <= 1.3.2 versions.

Fix: after 1.3.2
Fix from $1,600 2023-07-25
Theroof MEDIUM 6.1
CVE-2023-29430

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions.

Fix: after 1.0.3
Fix from $1,600 2023-06-26
Monolit MEDIUM 6.1
CVE-2023-25041

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions.

Fix: after 2.0.6
Fix from $1,600 2023-04-07
Outdoor MEDIUM 6.1
CVE-2023-29236

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions.

Fix: 3.9.7+
Fix from $1,600 2023-04-07
Citybook MEDIUM 6.1
CVE-2019-20210

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.

Fix: 1.0.6 / 1.2.2+
Fix from $1,600 2020-01-13
Citybook MEDIUM 6.1
CVE-2019-20211

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, L…

Fix: 1.0.6 / 1.2.2+
Fix from $1,600 2020-01-13
Citybook MEDIUM 6.1
CVE-2019-20212

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/pa…

Fix: 1.0.6 / 1.2.2+
Fix from $1,600 2020-01-13
Citybook HIGH 7.5
CVE-2019-20209

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR…

Fix: 1.0.6 / 1.2.2+
Fix from $1,950 2020-01-13