Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Form Vibes MEDIUM 5.4
CVE-2024-5309

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missi…

Fix: 1.4.13+
Fix from $1,600 2024-09-05
Form Vibes MEDIUM 6.5
CVE-2024-5325

The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all versions up to, and including, 1.4.10 du…

Fix: 1.4.11+
Fix from $1,600 2024-07-12
Form Vibes HIGH 7.2
CVE-2022-3764

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

Fix: 1.4.6+
Fix from $1,950 2024-01-16
Wp Mail Log HIGH 8.8
CVE-2023-51410

Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.

Fix: after 1.1.2
Fix from $1,950 2023-12-29
Wp Mail Log HIGH 8.8
CVE-2023-5674EPSS 11%

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL …

Fix: 1.1.3+
Fix from $1,950 2023-12-26
Wp Mail Log HIGH 8.8
CVE-2023-5645

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL …

Fix: 1.1.3+
Fix from $1,950 2023-12-26
Wp Mail Log HIGH 8.8
CVE-2023-5673

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to u…

Fix: 1.1.3+
Fix from $1,950 2023-12-26
Wp Mail Log HIGH 7.6
CVE-2023-5644

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view a…

Fix: 1.1.3+
Fix from $1,950 2023-12-26
Wp Mail Log MEDIUM 6.5
CVE-2023-5672

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file i…

Fix: 1.1.3+
Fix from $1,600 2023-12-26
Redirect 404 Error Page To Homepage Or Custom Page With Logs HIGH 7.2
CVE-2023-47530

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or …

Fix: 1.8.8+
Fix from $1,950 2023-12-18
Wp Mail Log MEDIUM 6.1
CVE-2023-3088

The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to i…

Fix: 1.1.2+
Fix from $1,600 2023-07-12
Anywhere Elementor MEDIUM 5.3
CVE-2023-0443

The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscript…

Fix: 1.2.8+
Fix from $1,600 2023-05-30
Wp Mail Log HIGH 8.8
CVE-2022-45807

Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions.

Fix: 1.0.2+
Fix from $1,950 2023-02-02
Redirect 404 Error Page To Homepage Or Custom Page With Logs MEDIUM 6.5
CVE-2021-24767

The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which coul…

Fix: 1.7.9+
Fix from $1,600 2021-11-08