Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wellspring HIGH 8.1
CVE-2025-67934

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring wel…

Fix: 2.8+
Fix from $1,950 2026-01-08
Optimize HIGH 8.1
CVE-2025-67935

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optim…

Fix: 2.4+
Fix from $1,950 2026-01-08
Curly HIGH 8.1
CVE-2025-67936

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly al…

Fix: 3.3+
Fix from $1,950 2026-01-08
Hendon HIGH 8.1
CVE-2025-67937

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon …

Fix: 1.7+
Fix from $1,950 2026-01-08
Lekker HIGH 8.1
CVE-2025-69034

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker …

Fix: after 1.8
Fix from $1,950 2025-12-30
Backpack Traveler MEDIUM 5.4
CVE-2025-69030

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Conf…

Fix: after 2.10.3
Fix from $1,600 2025-12-30
Fivestar MEDIUM 5.4
CVE-2025-69032

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Incorrectly Configured Access Con…

Fix: after 1.7
Fix from $1,600 2025-12-30
Wilmer HIGH 8.8
CVE-2025-67515

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer …

Fix: 3.5+
Fix from $1,950 2025-12-09
Wanderland HIGH 8.1
CVE-2025-39467

Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from …

Fix: 1.7.2+
Fix from $1,950 2025-11-06
Dor HIGH 8.1
CVE-2025-39466

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows…

Fix: 2.4.1+
Fix from $1,950 2025-11-06
Bard MEDIUM 5.4
CVE-2025-64368

Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a thro…

Fix: 1.7+
Fix from $1,600 2025-10-31
Qi Addons For Elementor MEDIUM 5.4
CVE-2025-6252

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and inclu…

Fix: 1.9.2+
Fix from $1,600 2025-06-28
Mediclinic CRITICAL 9.8
CVE-2025-49295

Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This issue affects MediClinic: from …

Fix: 2.2+
Fix from $2,300 2025-06-09
Grandprix CRITICAL 9.8
CVE-2025-49296

Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a…

Fix: 1.6.1+
Fix from $2,300 2025-06-09
Grill And Chow CRITICAL 9.8
CVE-2025-49297

Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.This issue affects Grill and C…

Fix: 1.6.1+
Fix from $2,300 2025-06-09
Wilmer CRITICAL 9.8
CVE-2025-39494

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer …

Fix: 3.4.2+
Fix from $2,300 2025-05-23
Backpack Traveler HIGH 8.1
CVE-2025-39490

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Backpack Trave…

Fix: 2.10.3+
Fix from $1,950 2025-05-23
Foton HIGH 8.1
CVE-2025-39458

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Foton foton al…

Fix: 2.6.1+
Fix from $1,950 2025-05-19
Qi Blocks MEDIUM 5.4
CVE-2025-1626

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post…

Fix: 1.4+
Fix from $1,600 2025-05-19
Qi Blocks MEDIUM 5.4
CVE-2025-1627

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the…

Fix: 1.4+
Fix from $1,600 2025-05-19
Qi Blocks MEDIUM 5.4
CVE-2025-1625

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post w…

Fix: 1.4+
Fix from $1,600 2025-05-19
Qi Addons For Elementor MEDIUM 5.4
CVE-2024-13699

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter in all versions up to, and i…

Fix: after 1.8.7
Fix from $1,600 2025-02-04
Qode Essential Addons HIGH 8.8
CVE-2024-50457

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qode Essential Addons q…

Fix: 1.6.4+
Fix from $1,950 2024-10-28
Qi Blocks HIGH 8.8
CVE-2024-49690

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.Thi…

Fix: 1.3.3+
Fix from $1,950 2024-10-23
Qi Blocks MEDIUM 5.4
CVE-2024-38712

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi …

Fix: 1.3.1+
Fix from $1,600 2024-07-20
Qi Addons For Elementor HIGH 7.5
CVE-2024-4887

The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior'…

Fix: 1.7.3+
Fix from $1,950 2024-06-07
Qi Blocks MEDIUM 5.4
CVE-2024-5221

The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, …

Fix: 1.3.0+
Fix from $1,600 2024-06-06
Qi Addons For Elementor MEDIUM 5.4
CVE-2024-4364

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button widgets in all versions up to, …

Fix: after 1.7.3
Fix from $1,600 2024-06-06
Qi Addons For Elementor HIGH 8.8
CVE-2023-47679

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QODE Interactive Qi Addons For Elementor allows PHP L…

Fix: 1.6.4+
Fix from $1,950 2024-05-17
Qi Addons For Elementor MEDIUM 5.4
CVE-2024-3309

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget's attributes in all versions u…

Fix: after 1.7.0
Fix from $1,600 2024-04-27