Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hostel MEDIUM 6.1
CVE-2025-6234

The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cro…

Fix: 1.1.5.8+
Fix from $1,600 2025-07-10
Watu Quiz MEDIUM 6.1
CVE-2025-30844

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz watu allows Reflected XSS.This is…

Fix: 3.4.3+
Fix from $1,600 2025-04-01
Watu Quiz HIGH 8.8
CVE-2024-53792

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This is…

Fix: 3.4.3+
Fix from $1,950 2024-12-02
Namaste\! Lms MEDIUM 6.1
CVE-2024-50407

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS namaste-lms allows Reflected X…

Fix: 2.6.3+
Fix from $1,600 2024-10-29
Namaste\! Lms MEDIUM 5.4
CVE-2024-50409

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS namaste-lms allows Stored XSS.…

Fix: 2.6.3+
Fix from $1,600 2024-10-29
Namaste\! Lms MEDIUM 5.4
CVE-2024-50410

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS namaste-lms allows Stored XSS.…

Fix: 2.6.4.1+
Fix from $1,600 2024-10-29
Namaste\! Lms HIGH 8.8
CVE-2024-50408

Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a thr…

Fix: 2.6.4+
Fix from $1,950 2024-10-28
Hostel MEDIUM 5.9
CVE-2024-3753

The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cro…

Fix: 1.1.5.3+
Fix from $1,600 2024-07-13
Watu Quiz MEDIUM 5.4
CVE-2024-2640

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've …

Fix: 3.4.1.2+
Fix from $1,600 2024-07-12
Watu Quiz MEDIUM 5.4
CVE-2024-0873

The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shortcode in all versions up to, …

Fix: 3.4.1.1+
Fix from $1,600 2024-04-09
Arigato Autoresponder And Newsletter HIGH 8.8
CVE-2023-47686

Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 versions.

Fix: after 2.7.2.2
Fix from $1,950 2023-11-16
Namaste\! Lms MEDIUM 6.1
CVE-2023-4602

The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including…

Fix: 2.6.1.2+
Fix from $1,600 2023-11-15
Watu Quiz MEDIUM 6.1
CVE-2023-30483

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.9.2 versions.

Fix: after 3.3.9.2
Fix from $1,600 2023-08-14
Watu Quiz CRITICAL 9.8
CVE-2015-10111

A vulnerability was found in Watu Quiz Plugin up to 2.6.7 on WordPress. It has been rated as critical. This issue affects the function watu_exams of …

Fix: 2.6.8+
Fix from $2,300 2023-06-04
Arigato Autoresponder And Newsletter MEDIUM 6.1
CVE-2023-25020

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.

Fix: after 2.7.1.1
Fix from $1,600 2023-04-07
Arigato Autoresponder And Newsletter MEDIUM 5.4
CVE-2023-25061

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.

Fix: after 2.7.1.1
Fix from $1,600 2023-04-07
Watu Quiz MEDIUM 6.1
CVE-2023-0968

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions…

Fix: after 3.3.9
Fix from $1,600 2023-03-03
Watu Quiz MEDIUM 6.1
CVE-2023-0428

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Fix: 3.3.8.2+
Fix from $1,600 2023-02-21
Chained Quiz MEDIUM 6.1
CVE-2022-4208

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'datef' parameter on the 'chainedquiz_list' page in ver…

Fix: after 1.3.2
Fix from $1,600 2022-12-02
Chained Quiz MEDIUM 6.1
CVE-2022-4209

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pointsf' parameter on the 'chainedquiz_list' page in v…

Fix: after 1.3.2
Fix from $1,600 2022-12-02
Chained Quiz MEDIUM 6.1
CVE-2022-4210

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dnf' parameter on the 'chainedquiz_list' page in versi…

Fix: after 1.3.2
Fix from $1,600 2022-12-02
Chained Quiz MEDIUM 6.1
CVE-2022-4211

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'emailf' parameter on the 'chainedquiz_list' page in ve…

Fix: after 1.3.2
Fix from $1,600 2022-12-02
Chained Quiz MEDIUM 6.1
CVE-2022-4212

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'chainedquiz_list' page in versi…

Fix: after 1.3.2
Fix from $1,600 2022-12-02
Chained Quiz MEDIUM 6.1
CVE-2022-4213

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dn' parameter on the 'chainedquiz_list' page in versio…

Fix: after 1.3.2.2
Fix from $1,600 2022-12-02
Chained Quiz MEDIUM 6.1
CVE-2022-4214

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter on the 'chainedquiz_list' page in versio…

Fix: after 1.3.2.3
Fix from $1,600 2022-12-02
Chained Quiz MEDIUM 6.1
CVE-2022-4215

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in vers…

Fix: after 1.3.2.3
Fix from $1,600 2022-12-02
Chained Quiz MEDIUM 5.4
CVE-2021-24690

The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.

Fix: 1.2.7.2+
Fix from $1,600 2021-10-11
Moolamojo MEDIUM 6.1
CVE-2021-38358

The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.p…

Fix: after 0.7.4.1
Fix from $1,600 2021-09-10
Konnichiwa MEDIUM 6.1
CVE-2021-38317

The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in the ~/views/subscriptions.ht…

Fix: after 0.8.3
Fix from $1,600 2021-09-09
Chained Quiz CRITICAL 9.8
CVE-2018-14502

controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL com…

Fix: 1.0.9+
Fix from $2,300 2020-03-10