Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yop Poll MEDIUM 5.3
CVE-2022-1600

The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possib…

Fix: 6.4.3+
Fix from $1,600 2022-08-01
Yop Poll MEDIUM 5.4
CVE-2022-0205

The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before…

Fix: 6.3.5+
Fix from $1,600 2022-03-07
Yop Poll MEDIUM 5.4
CVE-2021-24833

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where…

Fix: 6.3.1+
Fix from $1,600 2021-11-17
Yop Poll MEDIUM 5.4
CVE-2021-24834

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options modul…

Fix: 6.3.1+
Fix from $1,600 2021-11-17
Yop Poll MEDIUM 6.1
CVE-2021-24885

The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cr…

Fix: 6.1.2+
Fix from $1,600 2021-10-25
Yop Poll MEDIUM 6.1
CVE-2021-24454

In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result li…

Fix: 6.2.8+
Fix from $1,600 2021-07-12
Yop Poll MEDIUM 6.1
CVE-2019-9914

The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.

Fix: 6.0.3+
Fix from $1,600 2019-03-22
Yop Poll MEDIUM 5.4
CVE-2017-2127

Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified…

Fix: after 5.8
Fix from $1,600 2017-04-28