Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Flow Plus MEDIUM 5.4
CVE-2024-49695

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allow…

Fix: 5.2.4+
Fix from $1,600 2024-10-24
Spiffy Calendar MEDIUM 6.1
CVE-2024-45458

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar …

Fix: 4.9.14+
Fix from $1,600 2024-09-15
Spiffy Calendar MEDIUM 5.4
CVE-2024-45457

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar …

Fix: 4.9.14+
Fix from $1,600 2024-09-15
Spiffy Calendar HIGH 7.2
CVE-2024-38692

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injec…

Fix: 4.9.12+
Fix from $1,950 2024-07-22
Spiffy Calendar MEDIUM 6.3
CVE-2024-30528

Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.

Fix: 4.9.11+
Fix from $1,600 2024-06-04
Wp Flow Plus MEDIUM 5.4
CVE-2024-35651

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus allows Store…

Fix: 5.2.3+
Fix from $1,600 2024-06-04
Spiffy Calendar MEDIUM 6.1
CVE-2024-30427

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected…

Fix: 4.9.10+
Fix from $1,600 2024-03-29
Spiffy Calendar MEDIUM 5.3
CVE-2024-0855

The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, l…

Fix: 4.9.9+
Fix from $1,600 2024-02-27
Spiffy Calendar MEDIUM 5.4
CVE-2023-49745

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XS…

Fix: 4.9.6+
Fix from $1,600 2023-12-14
Spiffy Calendar CRITICAL 9.8
CVE-2022-46859

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar …

Fix: after 4.9.1
Fix from $2,300 2023-11-03
Spiffy Calendar MEDIUM 6.1
CVE-2023-32122

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions.

Fix: after 4.9.3
Fix from $1,600 2023-08-18
Spiffy Calendar MEDIUM 5.4
CVE-2022-29434

Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete e…

Fix: after 4.9.0
Fix from $1,600 2022-05-20