CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7984
4.3 MEDIUM

The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to …

May 15, 2025
CVE-2024-7769
4.8 MEDIUM

The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-7762
3.7 LOW

The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes

May 15, 2025
CVE-2024-7761
6.1 MEDIUM

In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on …

May 15, 2025
CVE-2024-7759
4.8 MEDIUM

The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-7758
4.8 MEDIUM

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor …

May 15, 2025
CVE-2024-7556
4.8 MEDIUM

The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6809
9.8 CRITICAL

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an …

May 15, 2025
CVE-2024-6798
4.8 MEDIUM

The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6797
4.8 MEDIUM

The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6719
8.1 HIGH

The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to …

May 15, 2025
CVE-2024-6718
5.4 MEDIUM

The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

May 15, 2025
CVE-2024-6713
4.8 MEDIUM

The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-6712
6.1 MEDIUM

The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 15, 2025
CVE-2024-6711
3.5 LOW

The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as …

May 15, 2025
CVE-2024-6708
4.8 MEDIUM

The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows …

May 15, 2025
CVE-2024-6693
4.8 MEDIUM

The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-6690
6.1 MEDIUM

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

May 15, 2025
CVE-2024-6668
5.4 MEDIUM

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role …

May 15, 2025
CVE-2024-6667
6.1 MEDIUM

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading …

May 15, 2025
CVE-2024-6665
4.8 MEDIUM

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users …

May 15, 2025
CVE-2024-6584
9.1 CRITICAL

The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.

May 15, 2025
CVE-2024-6486
7.2 HIGH

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, …

May 15, 2025
CVE-2024-6478
4.8 MEDIUM

The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-6462
4.8 MEDIUM

The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-6335
4.8 MEDIUM

The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-6159
9.8 CRITICAL

The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL …

May 15, 2025
CVE-2024-5440
5.4 MEDIUM

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a …

May 15, 2025
CVE-2024-5026
4.8 MEDIUM

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-4665
6.4 MEDIUM

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature …

May 15, 2025
CVE-2024-4091
3.5 LOW

The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-4004
3.5 LOW

The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-4002
3.5 LOW

The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege …

May 15, 2025
CVE-2024-3996
3.5 LOW

The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-3901
6.8 MEDIUM

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed …

May 15, 2025
CVE-2024-3062
4.8 MEDIUM

The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, which could allow high privilege …

May 15, 2025
CVE-2024-2869
4.8 MEDIUM

The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-2643
4.8 MEDIUM

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some …

May 15, 2025
CVE-2024-1663
4.8 MEDIUM

The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users …

May 15, 2025
CVE-2024-13865
6.1 MEDIUM

The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-13828
6.1 MEDIUM

The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-13823
6.1 MEDIUM

The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 15, 2025
CVE-2024-13730
4.8 MEDIUM

The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-13729
4.8 MEDIUM

The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-13727
6.1 MEDIUM

The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-13621
4.8 MEDIUM

The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-13619
6.1 MEDIUM

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-13616
4.8 MEDIUM

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege …

May 15, 2025
CVE-2024-13486
4.8 MEDIUM

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-13482
4.8 MEDIUM

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.