Total
37283 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-25101 | 1 Anti-malware Security And Brute-force Firewall Project | 1 Anti-malware Security And Brute-force Firewall | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be exploited by an admin against another admin user. | |||||
CVE-2021-25100 | 1 Givewp | 1 Givewp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25099 | 1 Givewp | 1 Givewp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25091 | 1 Ylefebvre | 1 Link Library | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25090 | 1 Wpsofts | 1 Portfolio Gallery\, Product Catalog - Grid Kit Portfolio | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embed | |||||
CVE-2021-25089 | 1 Updraftplus | 1 Updraftplus | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25088 | 1 Google Xml Sitemaps Project | 1 Google Xml Sitemaps | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
CVE-2021-25086 | 1 Advanced Page Visit Counter Project | 1 Advanced Page Visit Counter | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it | |||||
CVE-2021-25085 | 1 Pluginus | 1 Woocommerce Products Filter | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25083 | 1 Roundupwp | 1 Registrations For The Events Calendar | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25080 | 1 Crmperks | 1 Contact Form Entries | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry | |||||
CVE-2021-25079 | 1 Crmperks | 1 Contact Form Entries | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page | |||||
CVE-2021-25078 | 1 Wpaffiliatemanager | 1 Affiliates Manager | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests. | |||||
CVE-2021-25077 | 1 Visser | 1 Store Toolkit For Woocommerce | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25071 | 1 Inpsyde | 1 Akismet Privacy Policies | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25067 | 1 Pluginops | 1 Landing Page | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page. | |||||
CVE-2021-25066 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-25065 | 1 Smashballoon | 1 Smash Balloon Social Post Feed | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page. | |||||
CVE-2021-25063 | 1 Cf7skins | 1 Contact Form 7 Skins | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25062 | 1 Villatheme | 1 Orders Tracking For Woocommerce | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |