Total
37754 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24904 | 1 Lenderd | 1 Mortgage Calculators Wp | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24903 | 1 Codeasily | 1 Grand Flagallery | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24902 | 1 Typebot | 1 Typebot | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24901 | 1 Securemoz | 1 Security Audit | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24900 | 1 Wpmanageninja | 1 Ninja Tables | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2021-24899 | 1 Media-tags Project | 1 Media-tags | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed. | |||||
CVE-2021-24898 | 1 Editable-table Project | 1 Editable Table | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2021-24897 | 1 Viitorcloud | 1 Add Subtitle | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks | |||||
CVE-2021-24896 | 1 Calderaforms | 1 Caldera Forms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24895 | 1 Webbigt | 1 Cybersoldier | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2021-24891 | 1 Elementor | 1 Website Builder | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue. | |||||
CVE-2021-24888 | 1 Imageboss | 1 Imageboss | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high privilege users to perform Cross-Site Scripting attacks | |||||
CVE-2021-24885 | 1 Yop-poll | 1 Yop-poll | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-24884 | 1 Strategy11 | 1 Formidable Form Builder | 2024-11-21 | 6.8 MEDIUM | 9.6 CRITICAL |
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These actions include stealing the users account by changing their password or allowing attackers to submit their own code through an authenticated user resulting in Remote Code Execution. If an authenticated user who is able to edit Wordpress PHP Code in any kind, clicks the malicious link, PHP code can be edited. | |||||
CVE-2021-24883 | 1 Essentialplugin | 1 Popup Anything | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks | |||||
CVE-2021-24882 | 1 Tribulant | 1 Slideshow Gallery | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |||||
CVE-2021-24880 | 1 Supportcandy | 1 Supportcandy | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks | |||||
CVE-2021-24878 | 1 Supportcandy | 1 Supportcandy | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2021-24876 | 1 Roundupwp | 1 Registrations For The Events Calendar | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-24875 | 1 Implecode | 1 Ecommerce Product Catalog | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue |