11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-24798
WP Header Images Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting issue

CVE-2013-5988
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.

CVE-2015-9233
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.

CVE-2023-2601
wpbrutalai Web Database Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.

CVE-2021-24339
Pods – Custom Content Types and Fields Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 1 PoC

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.

CVE-2021-24274
Ultimate Maps by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.5%
2021 CWE-79 2 PoCs

The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-24737
Comments – wpDiscuz Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-24617
GamePress – The Game Database Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues

CVE-2015-5533
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
9.5%
2015 3 PoCs

SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

CVE-2023-0064
eVision Responsive Column Layout Shortcodes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The eVision Responsive Column Layout Shortcodes WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2021-24343
iFlyChat – WordPress Chat Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-24420
Request a Quote Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.

CVE-2014-9173
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
2.2%
2014 1 PoC

SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.

CVE-2013-7292
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-time AD password.

CVE-2015-9333
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2015 1 PoC

The cforms2 plugin before 14.6.10 for WordPress has SQL injection.

CVE-2021-24234
Ivory Search – WordPress Search Plugin Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack.

CVE-2021-24774
Check & Log Email Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues

CVE-2021-24879
SupportCandy – Helpdesk & Support Ticket System Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

CVE-2023-3328
Custom Field For WP Job Manager Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Custom Field For WP Job Manager WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-24846
Ni WooCommerce Custom Order Status Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber