Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nd Shortcodes MEDIUM 5.4
CVE-2024-5220

The ND Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's upload feature in all versions up to, and includ…

Fix: 7.6+
Fix from $1,600 2024-05-25
Restaurant Reservations MEDIUM 5.4
CVE-2023-51403

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored X…

Fix: after 1.8
Fix from $1,600 2024-02-12
Nd Shortcodes HIGH 8.8
CVE-2023-1273

The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include funct…

Fix: 7.0+
Fix from $1,950 2023-07-04
Nd Shortcodes MEDIUM 5.4
CVE-2022-4623

The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page…

Fix: 7.0+
Fix from $1,600 2023-07-04
Cost Calculator MEDIUM 5.4
CVE-2023-0165

The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/…

Fix: after 1.8
Fix from $1,600 2023-03-06
Cost Calculator MEDIUM 5.4
CVE-2023-1155

The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up t…

Fix: after 1.8
Fix from $1,600 2023-03-02
Hotel Booking MEDIUM 5.4
CVE-2022-29443

Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 a…

Fix: after 3.0
Fix from $1,600 2022-06-15
Nd Travel MEDIUM 5.4
CVE-2022-27859

Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin…

Fix: after 2.0
Fix from $1,600 2022-06-15
Cost Calculator MEDIUM 5.4
CVE-2021-24821

The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the…

Fix: 1.6+
Fix from $1,600 2022-03-07