CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9663
5.4 MEDIUM

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-9662
5.4 MEDIUM

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-9645
5.4 MEDIUM

The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options …

May 15, 2025
CVE-2024-9599
5.4 MEDIUM

The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-9450
6.5 MEDIUM

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, …

May 15, 2025
CVE-2024-9390
4.8 MEDIUM

The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-9238
5.4 MEDIUM

The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to …

May 15, 2025
CVE-2024-9236
4.8 MEDIUM

The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-9233
4.3 MEDIUM

The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-9227
4.8 MEDIUM

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could …

May 15, 2025
CVE-2024-9182
4.8 MEDIUM

The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-8854
5.4 MEDIUM

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8851
5.4 MEDIUM

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8759
4.8 MEDIUM

The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-8703
6.1 MEDIUM

The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to …

May 15, 2025
CVE-2024-8702
4.8 MEDIUM

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-8701
4.8 MEDIUM

The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-8670
4.8 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-8620
4.8 MEDIUM

The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8619
4.8 MEDIUM

The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8618
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8617
4.8 MEDIUM

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to …

May 15, 2025
CVE-2024-8542
4.8 MEDIUM

The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-8493
4.8 MEDIUM

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-8492
4.8 MEDIUM

The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to …

May 15, 2025
CVE-2024-8426
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8398
4.3 MEDIUM

The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make …

May 15, 2025
CVE-2024-8397
5.4 MEDIUM

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting …

May 15, 2025
CVE-2024-8286
6.5 MEDIUM

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform …

May 15, 2025
CVE-2024-8284
4.8 MEDIUM

The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors …

May 15, 2025
CVE-2024-8245
4.3 MEDIUM

The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

May 15, 2025
CVE-2024-8187
4.8 MEDIUM

The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-8095
6.1 MEDIUM

The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2024-8094
6.5 MEDIUM

The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-8090
6.1 MEDIUM

The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 15, 2025
CVE-2024-8085
6.1 MEDIUM

The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2024-8082
4.3 MEDIUM

The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-8050
4.3 MEDIUM

The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make …

May 15, 2025
CVE-2024-8032
6.1 MEDIUM

The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

May 15, 2025
CVE-2024-8031
6.5 MEDIUM

The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, …

May 15, 2025
CVE-2024-8009
4.3 MEDIUM

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

May 15, 2025
CVE-2024-7984
4.3 MEDIUM

The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to …

May 15, 2025
CVE-2024-7769
4.8 MEDIUM

The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-7761
6.1 MEDIUM

In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on …

May 15, 2025
CVE-2024-7759
4.8 MEDIUM

The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-7758
4.8 MEDIUM

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor …

May 15, 2025
CVE-2024-7556
4.8 MEDIUM

The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6798
4.8 MEDIUM

The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6797
4.8 MEDIUM

The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-6718
5.4 MEDIUM

The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

May 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.