Search Results (44418 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-36417 1 3d Tag Cloud Project 1 3d Tag Cloud 2025-02-20 6.1 Medium
Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in 3D Tag Cloud plugin <= 3.8 at WordPress.
CVE-2022-40215 1 Tabs Project 1 Tabs 2025-02-20 3.4 Low
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress.
CVE-2021-36839 1 Spacexchimp 1 Social Media Follow Buttons Bar 2025-02-20 4.8 Medium
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress.
CVE-2021-36830 1 Comment Guestbook Project 1 Comment Guestbook 2025-02-20 4.8 Medium
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress.
CVE-2021-36855 1 Bookingultrapro 1 Booking Ultra Pro Appointments Booking Calendar 2025-02-20 6.1 Medium
Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
CVE-2022-33978 1 Fontmeister Project 1 Fontmeister 2025-02-20 6.1 Medium
Reflected Cross-Site Scripting (XSS) vulnerability FontMeister plugin <= 1.08 at WordPress.
CVE-2021-36899 1 Asset Cleanup\ 1 Page Speed Booster Project 2025-02-20 4.8 Medium
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Booster plugin <= 1.3.8.4 at WordPress.
CVE-2022-26375 1 Abpressoptimizer 1 Ab Press Optimizer 2025-02-20 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology AB Press Optimizer plugin <= 1.1.1 on WordPress.
CVE-2022-41638 1 Chop-chop 1 Pop-up Chop Chop 2025-02-20 5.4 Medium
Auth. Stored Cross-Site Scripting (XSS) in Pop-Up Chop Chop plugin <= 2.1.7 on WordPress.
CVE-2022-40311 1 Fatcatapps 1 Analytics Cat 2025-02-20 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress.
CVE-2021-36863 1 Expresstech 1 Quiz And Survey Master 2025-02-20 5.4 Medium
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-36864 1 Expresstech 1 Quiz And Survey Master 2025-02-20 3.4 Low
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2022-44576 1 Agenteasy Properties Project 1 Agenteasy Properties 2025-02-20 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in AgentEasy Properties plugin <= 1.0.4 on WordPress.
CVE-2022-44586 1 Am-hili Project 1 Am-hili 2025-02-20 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) in Ayoub Media AM-HiLi plugin <= 1.0 on WordPress.
CVE-2022-36428 1 Rockcontent 1 Rock Convert 2025-02-20 4.8 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress.
CVE-2022-44628 1 Jumpdemand 1 4ecps Web Forms 2025-02-20 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on WordPress.
CVE-2022-30545 1 5-anker 1 5 Anker Connect 2025-02-20 4.8 Medium
Auth. Reflected Cross-Site Scripting (XSS) vulnerability in 5 Anker Connect plugin <= 1.2.6 on WordPress.
CVE-2022-36357 1 Webpsilon 1 Ultimate Tables 2025-02-20 6.1 Medium
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.
CVE-2024-4036 1 Athemes 1 Sydney Toolbox 2025-02-20 6.4 Medium
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-2958 1 Svs-websoft 1 Svs Pricing Tables 2025-02-20 4.4 Medium
The SVS Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pricing table settings in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.