Export limit exceeded: 374459 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 374459 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 374459 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374459 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-1626 | 1 Qodeinteractive | 1 Qi Blocks | 2026-01-09 | 5.4 Medium |
| The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2025-1625 | 1 Qodeinteractive | 1 Qi Blocks | 2026-01-09 | 5.4 Medium |
| The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2025-1382 | 1 Lordlinus | 1 Contact Us | 2026-01-09 | 6.1 Medium |
| The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | ||||
| CVE-2024-9828 | 1 Taskbuilder | 1 Taskbuilder | 2026-01-09 | 4.1 Medium |
| The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks | ||||
| CVE-2024-9458 | 1 Reservit | 1 Reservit Hotel | 2026-01-09 | 4.8 Medium |
| The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-3643 | 2 Mndpsingh287, Newsletter Popup Project | 2 Newsletter Popup, Newsletter Popup | 2026-01-09 | 8.8 High |
| The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack | ||||
| CVE-2024-3406 | 1 Goprayer | 1 Wp Prayer | 2026-01-09 | 8.8 High |
| The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack | ||||
| CVE-2024-13669 | 1 Margiov | 1 Calendapp | 2026-01-09 | 6.1 Medium |
| The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | ||||
| CVE-2024-13352 | 1 Alwayscurious | 1 Legull | 2026-01-09 | 7.1 High |
| The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | ||||
| CVE-2024-13219 | 1 Waelhassan | 1 Privacy Policy Genius | 2026-01-09 | 6.1 Medium |
| The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | ||||
| CVE-2024-12774 | 1 Pulseextensions | 1 Altra Side Menu | 2026-01-09 | 6.5 Medium |
| The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack | ||||
| CVE-2024-10710 | 2 Antongorodezkiy, Yadisk Files | 2 Yadisk Files, Yadisk Files | 2026-01-09 | 3.5 Low |
| The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2023-5971 | 1 Pdfcrowd | 1 Save As Pdf | 2026-01-09 | 4.8 Medium |
| The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2015-10140 | 1 Connekthq | 1 Ajax Load More | 2026-01-09 | 8.8 High |
| The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files. | ||||
| CVE-2021-4436 | 1 Wp3dprinting | 1 3dprint Lite | 2026-01-09 | 9.8 Critical |
| The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache. | ||||
| CVE-2023-6503 | 1 Paulgriffinpetty | 1 Wp Plugin Lister | 2026-01-09 | 5.4 Medium |
| The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | ||||
| CVE-2024-0239 | 1 Ari-soft | 1 Contact Form 7 Connector | 2026-01-09 | 6.1 Medium |
| The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators. | ||||
| CVE-2023-0094 | 1 Qoders | 1 Upqode Google Maps | 2026-01-09 | 5.4 Medium |
| The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2022-23179 | 1 Themehunk | 1 Contact Form \& Lead Form Elementor Builder | 2026-01-09 | 4.8 Medium |
| The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
| CVE-2021-24870 | 1 Wpfastestcache | 1 Wp Fastest Cache | 2026-01-09 | 6.1 Medium |
| The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload | ||||