Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tour Master HIGH 8.8
CVE-2024-13369

The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all ver…

Fix: 5.3.8+
Fix from $1,950 2025-02-18
Tour Master HIGH 7.1
CVE-2024-12400

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scr…

Fix: 5.3.5+
Fix from $1,950 2025-01-30
Goodlayers Core MEDIUM 6.5
CVE-2024-12163

The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.

Fix: 2.1.3+
Fix from $1,600 2025-01-30
Tour Master MEDIUM 6.1
CVE-2024-11356

The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthe…

Fix: 5.3.4+
Fix from $1,600 2025-01-06
Goodlayers Core MEDIUM 5.9
CVE-2024-11357

The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor ro…

Fix: 2.0.10+
Fix from $1,600 2025-01-02
Travel Tour MEDIUM 6.1
CVE-2024-11846

The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used …

Fix: 5.2.4+
Fix from $1,600 2025-01-01
Good Learning Management System CRITICAL 9.8
CVE-2020-27481EPSS 10%

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, whic…

Fix: after 2.1.4
Fix from $2,300 2020-11-12