11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2014-8375
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2014 2 PoCs

SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php.

CVE-2013-1409
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
3.4%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php.

CVE-2015-5557
Software Genérico Windows
N/A
UNKNOWN
EPSS
47.0%
2015 3 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

CVE-2021-25091
Link Library Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-24664
School Management System – WPSchoolPress Web Windows
N/A
UNKNOWN
EPSS
1.4%
2021 CWE-79 2 PoCs

The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

CVE-2021-25078
Affiliates Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2021 CWE-79 1 PoC

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

CVE-2021-24546
Gutenberg Block Editor Toolkit – EditorsKit Web Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-94 1 PoC

The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code

CVE-2015-1579
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2015 2 PoCs

Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.

CVE-2021-24897
Add Subtitle Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

CVE-2021-24178
Business Directory Plugin – Easy Listing Directories for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

CVE-2013-1916
WordPress Plugin User Photo Web Windows
N/A
UNKNOWN
EPSS
34.8%
2013 CWE-434 1 PoC

In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

CVE-2015-6682
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.7%
2015 3 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-5584.

CVE-2021-24464
YouTube Embed, Playlist and Popup by WpDevArt Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.

CVE-2021-24409
Prismatic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.3%
2021 CWE-79 1 PoC

The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

CVE-2021-25114
Paid Memberships Pro Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2021 CWE-89 1 PoC

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CVE-2015-9384
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The relevant plugin before 1.0.8 for WordPress has XSS.

CVE-2021-24838
AnyComment Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2021 CWE-601 1 PoC

The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

CVE-2021-24713
Video Lessons Manager – Best Video Course LMS Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks

CVE-2014-8492
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.

CVE-2013-6796
Software Genérico Windows
N/A
UNKNOWN
EPSS
14.7%
2013 1 PoC

The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous bind.