Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Smartblog HIGH 7.5
CVE-2020-36972

SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract da…

No fix yet
Fix from $1,950 2026-01-28
Clasify Classified Listing MEDIUM 6.1
CVE-2024-12725

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading…

Fix: after 1.0.7
Fix from $1,600 2025-05-15
Essential Wp Real Estate MEDIUM 6.1
CVE-2025-23857

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SmartDataSoft Essential WP Real Estate essentia…

Fix: after 1.1.3
Fix from $1,600 2025-02-14
Essential Wp Real Estate MEDIUM 6.8
CVE-2024-13347

The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected…

Fix: after 1.1.3
Fix from $1,600 2025-02-03
Essential Wp Real Estate MEDIUM 5.3
CVE-2024-13318

The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_fun…

Fix: after 1.1.3
Fix from $1,600 2025-01-10
Smartblog CRITICAL 9.8
CVE-2021-37538EPSS 74%

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbit…

Fix: 4.06+
Fix from $2,300 2021-08-24
Car Repair Services \& Auto Mechanic MEDIUM 6.1
CVE-2021-24335

The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputtin…

Fix: 4.0+
Fix from $1,600 2021-06-01