Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 247 248 249 250 251 252 253 254 255 256 [257] 258 259 260 261 262 263 264 265 266 267 ... Result(s) : 324592

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
4.8 2025-05-15 CVE-2024-8187 cve The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros...
N/A 2025-05-15 CVE-2024-8618 cve The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Sto...
N/A 2025-05-15 CVE-2024-8619 cve The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cr...
N/A 2025-05-15 CVE-2024-8620 cve The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros...
N/A 2025-05-15 CVE-2024-8670 cve The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Sto...
N/A 2025-05-15 CVE-2024-8673 cve The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
N/A 2025-05-15 CVE-2024-8699 cve The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server eve...
N/A 2025-05-15 CVE-2024-8700 cve The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
N/A 2025-05-15 CVE-2024-8701 cve The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros...
N/A 2025-05-15 CVE-2025-0329 cve The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform St...
N/A 2025-05-15 CVE-2025-0687 cve The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leadin...
N/A 2025-05-15 CVE-2025-0688 cve The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leadin...
N/A 2025-05-15 CVE-2025-1033 cve The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Sit...
N/A 2025-05-15 CVE-2025-1286 cve The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site S...
N/A 2025-05-15 CVE-2025-1288 cve The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unau...
N/A 2025-05-15 CVE-2025-1289 cve The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros...
N/A 2025-05-15 CVE-2025-1303 cve The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting wh...
8.8 2025-05-15 CVE-2025-47785 cve Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not ...
4.8 2025-05-15 CVE-2025-47786 cve Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that allows any registered user to construct malicious JavaScript...
N/A 2025-05-15 CVE-2025-47787 cve Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security fla...
Page(s) : 1 ... 247 248 249 250 251 252 253 254 255 256 [257] 258 259 260 261 262 263 264 265 266 267 ... Result(s) : 324592