CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13384
4.8 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow …

May 15, 2025
CVE-2024-13383
4.8 MEDIUM

The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-13382
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-13357
4.8 MEDIUM

The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …

May 15, 2025
CVE-2024-13313
4.8 MEDIUM

The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-13128
4.8 MEDIUM

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-13127
4.8 MEDIUM

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-13053
4.8 MEDIUM

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-12874
4.8 MEDIUM

The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-12873
6.1 MEDIUM

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 15, 2025
CVE-2024-12812
7.5 HIGH

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an …

May 15, 2025
CVE-2024-12808
4.8 MEDIUM

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and …

May 15, 2025
CVE-2024-12800
4.8 MEDIUM

The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform …

May 15, 2025
CVE-2024-12770
4.8 MEDIUM

The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-12767
3.5 LOW

The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts

May 15, 2025
CVE-2024-12750
4.3 MEDIUM

The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-12743
4.8 MEDIUM

The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-12739
4.8 MEDIUM

The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-12735
7.2 HIGH

The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and …

May 15, 2025
CVE-2024-12734
6.1 MEDIUM

The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it …

May 15, 2025
CVE-2024-12733
6.1 MEDIUM

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-12732
6.1 MEDIUM

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-12726
6.1 MEDIUM

The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-12725
6.1 MEDIUM

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 15, 2025
CVE-2024-12724
6.1 MEDIUM

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

May 15, 2025
CVE-2024-12722
5.4 MEDIUM

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back …

May 15, 2025
CVE-2024-12716
4.8 MEDIUM

The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-12680
4.8 MEDIUM

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-12679
4.8 MEDIUM

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-12301
6.5 MEDIUM

The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users …

May 15, 2025
CVE-2024-12282
6.1 MEDIUM

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2024-11843
4.8 MEDIUM

The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-11719
6.1 MEDIUM

The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2024-11718
5.4 MEDIUM

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor …

May 15, 2025
CVE-2024-11502
5.4 MEDIUM

The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a …

May 15, 2025
CVE-2024-11373
4.3 MEDIUM

The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-11372
7.2 HIGH

The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform …

May 15, 2025
CVE-2024-11269
7.2 HIGH

The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform …

May 15, 2025
CVE-2024-11267
8.8 HIGH

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with …

May 15, 2025
CVE-2024-11266
4.8 MEDIUM

The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-11221
4.8 MEDIUM

The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege …

May 15, 2025
CVE-2024-11190
4.8 MEDIUM

The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-11189
4.8 MEDIUM

The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users …

May 15, 2025
CVE-2024-11141
6.1 MEDIUM

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers …

May 15, 2025
CVE-2024-11140
3.5 LOW

The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow …

May 15, 2025
CVE-2024-11109
4.8 MEDIUM

The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-10818
5.4 MEDIUM

The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

May 15, 2025
CVE-2024-10677
4.3 MEDIUM

The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

May 15, 2025
CVE-2024-10639
4.8 MEDIUM

The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-10634
4.3 MEDIUM

The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make …

May 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.