Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cp Contact Form MEDIUM 6.5
CVE-2024-13758

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This i…

Fix: 1.3.53+
Fix from $1,600 2025-01-30
Cp Blocks HIGH 8.8
CVE-2023-41732

Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Blocks plugin <= 1.0.20 versions.

Fix: 1.0.21+
Fix from $1,950 2023-10-06
Corner Ad MEDIUM 6.5
CVE-2022-3427

The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56. This is due to missing or in…

Fix: after 1.0.56
Fix from $1,600 2022-12-15
Appointment Hour Booking HIGH 7.8
CVE-2022-4034

The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for…

Fix: after 1.3.72
Fix from $1,950 2022-11-29
Appointment Hour Booking MEDIUM 6.1
CVE-2022-4035

The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, an…

Fix: after 1.3.72
Fix from $1,600 2022-11-29
Appointment Hour Booking MEDIUM 5.3
CVE-2022-4036

The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of…

Fix: after 1.3.72
Fix from $1,600 2022-11-29
Appointment Hour Booking HIGH 8.8
CVE-2022-41692

Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.

Fix: 1.3.72+
Fix from $1,950 2022-11-18
Cp Image Store With Slideshow CRITICAL 9.8
CVE-2022-1692EPSS 11%

The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQ…

Fix: 1.0.68+
Fix from $2,300 2022-06-08
Appointment Hour Booking MEDIUM 5.4
CVE-2021-24712

The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.

Fix: 1.3.17+
Fix from $1,600 2021-10-11
Calendar Event Multi View MEDIUM 6.1
CVE-2021-24498

The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them …

Fix: 1.4.01+
Fix from $1,600 2021-08-02
Corner Ad MEDIUM 6.1
CVE-2017-18579

The corner-ad plugin before 1.0.8 for WordPress has XSS.

Fix: 1.0.8+
Fix from $1,600 2019-08-22
Appointment Hour Booking MEDIUM 6.1
CVE-2019-13505

The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.

No fix yet
Fix from $1,600 2019-07-11