Export limit exceeded: 381063 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 381063 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 381063 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 94404 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (94404 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-24397 1 Activemedia 1 Microcopy 2024-11-21 7.2 High
The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24396 1 Bestiaweb 1 Gseor 2024-11-21 7.2 High
A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24395 1 Geekwebsolution 1 Embed Youtube Video 2024-11-21 7.2 High
The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24394 1 Easy Testimonial Manager Project 1 Easy Testimonial Manager 2024-11-21 7.2 High
An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection
CVE-2021-24393 1 Comment Highlighter Project 1 Comment Highlighter 2024-11-21 7.2 High
A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24392 1 Swiftcrm 1 Club-management-software 2024-11-21 7.2 High
An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24391 1 Cashtomer Project 1 Cashtomer 2024-11-21 8.8 High
An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24390 1 Alipay Project 1 Alipay 2024-11-21 7.2 High
A proid GET parameter of the WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.
CVE-2021-24377 1 Autoptimize 1 Autoptimize 2024-11-21 8.1 High
The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.
CVE-2021-24356 1 Wpdeveloper 1 Simple 301 Redirects 2024-11-21 8.8 High
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.
CVE-2021-24354 1 Wpdeveloper 1 Simple 301 Redirects 2024-11-21 8.8 High
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
CVE-2021-24353 1 Wpdeveloper 1 Simple 301 Redirects 2024-11-21 8.8 High
The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.
CVE-2021-24352 1 Wpdeveloper 1 Simple 301 Redirects 2024-11-21 8.8 High
The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.
CVE-2021-24348 1 Wow-estore 1 Side Menu 2024-11-21 7.2 High
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue
CVE-2021-24347 1 Smartypantsplugins 1 Sp Project \& Document Manager 2024-11-21 8.8 High
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".
CVE-2021-24341 1 Xllentech 1 English Islamic Calendar 2024-11-21 8.8 High
When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection.
CVE-2021-24340 1 Veronalabs 1 Wp Statistics 2024-11-21 7.5 High
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.
CVE-2021-24337 1 Video-embed-box Project 1 Video-embed-box 2024-11-21 8.8 High
The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.
CVE-2021-24336 1 Zavedil 1 Flightlog 2024-11-21 7.2 High
The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users
CVE-2021-24312 1 Automattic 1 Wp Super Cache 2024-11-21 7.2 High
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.