Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jquery News Ticker MEDIUM 5.4
CVE-2023-5432

The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortcode in versions up to, and in…

Fix: after 3.1
Fix from $1,600 2023-12-19
Image Horizontal Reel Scroll Slideshow MEDIUM 5.4
CVE-2023-5413

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-gallery' shortcode in version…

Fix: after 13.3
Fix from $1,600 2023-12-19
Email Download Link MEDIUM 5.3
CVE-2023-36523

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link:…

Fix: after 3.7
Fix from $1,600 2023-11-30
Email Posts To Subscribers HIGH 7.5
CVE-2023-41735

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email posts to subscribers.This issue affects Email posts t…

Fix: after 6.2
Fix from $1,950 2023-11-30
Popup With Fancybox HIGH 8.8
CVE-2023-5465

The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.5 due to i…

Fix: after 3.5
Fix from $1,950 2023-11-22
Wp Anything Slider HIGH 8.8
CVE-2023-5466

The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.1 due to in…

Fix: after 9.1
Fix from $1,950 2023-11-22
Vertical Scroll Recent Registered User HIGH 8.8
CVE-2023-47671

Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy Vertical scroll recent.This issue affects Vertical scroll recent post: from n/a thro…

Fix: after 9.1
Fix from $1,950 2023-11-18
Email Posts To Subscribers CRITICAL 9.8
CVE-2022-46818

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopi Ramasamy Email posts to subscribers allows…

Fix: after 6.2
Fix from $2,300 2023-11-03
Vertical Marquee Plugin MEDIUM 6.5
CVE-2023-5436

The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 7.1 due to insu…

Fix: 7.2+
Fix from $1,600 2023-10-31
Wp Fade In Text News MEDIUM 6.5
CVE-2023-5437

The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to…

Fix: 12.1+
Fix from $1,600 2023-10-31
Wp Image Slideshow MEDIUM 6.5
CVE-2023-5438

The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to i…

Fix: 12.1+
Fix from $1,600 2023-10-31
Wp Photo Text Slider 50 MEDIUM 6.5
CVE-2023-5439

The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.0 due …

Fix: 8.1+
Fix from $1,600 2023-10-31
Jquery Accordion Slideshow MEDIUM 6.5
CVE-2023-5464

The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.1 d…

Fix: 8.2+
Fix from $1,600 2023-10-31
Image Horizontal Reel Scroll Slideshow MEDIUM 6.5
CVE-2023-5412

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and incl…

Fix: 13.3+
Fix from $1,600 2023-10-31
Image Vertical Reel Scroll Slideshow MEDIUM 6.5
CVE-2023-5428

The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and includ…

Fix: 9.1+
Fix from $1,600 2023-10-31
Information Reel MEDIUM 6.5
CVE-2023-5429

The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 10.0 due to ins…

Fix: 10.1+
Fix from $1,600 2023-10-31
Jquery News Ticker MEDIUM 6.5
CVE-2023-5430

The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.0 due to in…

Fix: 3.1+
Fix from $1,600 2023-10-31
Left Right Image Slideshow Gallery MEDIUM 6.5
CVE-2023-5431

The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and includin…

Fix: 12.1+
Fix from $1,600 2023-10-31
Message Ticker MEDIUM 6.5
CVE-2023-5433

The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.2 due to insuff…

Fix: 9.3+
Fix from $1,600 2023-10-31
Superb Slideshow Gallery MEDIUM 6.5
CVE-2023-5434

The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.1 du…

Fix: 13.2+
Fix from $1,600 2023-10-31
Up Down Image Slideshow Gallery MEDIUM 6.5
CVE-2023-5435

The Up down image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, …

Fix: 12.1+
Fix from $1,600 2023-10-31
Horizontal Scrolling Announcement HIGH 8.8
CVE-2023-4999

The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-scrolling] shortcode in versio…

Fix: after 9.2
Fix from $1,950 2023-10-20
Wp Tell A Friend Popup Form HIGH 8.8
CVE-2023-25463

Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy WP tell a friend popup form plugin <= 7.1 versions.

Fix: after 7.1
Fix from $1,950 2023-10-03
Horizontal Scrolling Announcement MEDIUM 5.4
CVE-2023-5001

The Horizontal scrolling announcement plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'horizontal-scrolling' shortcode in versi…

Fix: after 9.2
Fix from $1,600 2023-09-16