Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hash Elements MEDIUM 6.5
CVE-2025-22296

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Hash Elements hash-elements.This iss…

Fix: 1.5.1+
Fix from $1,600 2025-01-07
Hash Elements MEDIUM 5.3
CVE-2024-10802

The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_…

Fix: 1.4.8+
Fix from $1,600 2024-11-13
Hash Form MEDIUM 6.1
CVE-2024-9417

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in th…

Fix: 1.2.0+
Fix from $1,600 2024-10-05
Hash Form CRITICAL 9.8
CVE-2024-5085

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via d…

Fix: 1.1.1+
Fix from $2,300 2024-05-23
Hash Form CRITICAL 9.8
CVE-2024-5084EPSS 51%

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fil…

Fix: 1.1.1+
Fix from $2,300 2024-05-23
Hash Elements MEDIUM 5.4
CVE-2024-5177

The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter within multiple widgets in all versions u…

Fix: 1.3.9+
Fix from $1,600 2024-05-23
Hash Elements MEDIUM 5.4
CVE-2024-30426

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This…

Fix: 1.3.4+
Fix from $1,600 2024-03-29
Hashthemes Demo Importer HIGH 8.1
CVE-2021-39333

The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-i…

Fix: after 1.1.1
Fix from $1,950 2021-11-01