Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Event Rsvp And Simple Event Management MEDIUM 5.4
CVE-2025-5540

The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' sh…

Fix: after 4.1.0
Fix from $1,600 2025-06-26
Wp Easy Contact MEDIUM 6.4
CVE-2025-5539

The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'em…

Fix: 4.0.1+
Fix from $1,600 2025-06-04
Request A Quote MEDIUM 5.9
CVE-2024-6231

The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as a…

Fix: 2.4.1+
Fix from $1,600 2024-07-23
Youtube Video Gallery MEDIUM 5.3
CVE-2024-3268

The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of…

Fix: 3.4.0+
Fix from $1,600 2024-05-21
Youtube Video Gallery HIGH 8.8
CVE-2023-40558

Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3.3.5 versions.

Fix: 3.3.6+
Fix from $1,950 2023-10-03
Request A Quote HIGH 8.8
CVE-2022-2240

The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV fil…

Fix: after 2.3.7
Fix from $1,950 2022-07-25
Request A Quote MEDIUM 5.4
CVE-2021-24420

The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading …

Fix: 2.3.4+
Fix from $1,600 2021-07-12