Search Results (20757 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-7480 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
CVE-2013-7479 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
CVE-2013-7478 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
CVE-2013-7477 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
CVE-2013-7476 1 Simple Fields Project 1 Simple Fields 2024-11-21 N/A
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
CVE-2013-7475 1 Bestwebsoft 1 Contact Form 2024-11-21 N/A
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
CVE-2013-7472 1 Count Per Day Project 1 Count Per Day 2024-11-21 N/A
The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.
CVE-2013-5988 1 Semperplugins 1 All In One Seo Pack 2024-11-21 6.1 Medium
A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.
CVE-2013-5978 1 Cart66 1 Cart66 Lite Plugin 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php. NOTE: This issue may only cross privilege boundaries if used in combination with CVE-2013-5977.
CVE-2013-4693 1 Xorbin 1 Digital Flash Clock 2024-11-21 6.1 Medium
WordPress Xorbin Digital Flash Clock 1.0 has XSS
CVE-2013-4462 1 Portable Phpmyadmin Project 1 Portable Phpmyadmin 2024-11-21 9.1 Critical
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability
CVE-2013-4454 1 Getbutterfly 1 Portable-phpmyadmin 2024-11-21 9.1 Critical
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities
CVE-2013-4241 1 Hitmyserver 1 Hms Testimonials 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format parameter to the Settings - Default form (hms-testimonials-settings page); (6) name parameter in a Save action to the Settings - Custom Fields form (hms-testimonials-settings-fields page); or (7) name parameter in a Save action to the Settings - Template form (hms-testimonials-templates-new page).
CVE-2013-4144 1 Swfupload Project 1 Swfupload 2024-11-21 9.8 Critical
There is an object injection vulnerability in swfupload plugin for wordpress.
CVE-2013-3684 1 Imagely 1 Nextgen Gallery 2024-11-21 9.8 Critical
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
CVE-2013-2714 1 Podpress Project 1 Podpress 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.
CVE-2013-2109 1 Undolog 1 Wp Cleanfix 2024-11-21 8.8 High
WordPress plugin wp-cleanfix has Remote Code Execution
CVE-2013-2108 1 Undolog 1 Cleanfix 2024-11-21 5.4 Medium
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
CVE-2013-2011 1 Automattic 1 W3 Super Cache 2024-11-21 8.8 High
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
CVE-2013-2010 2 Automattic, Boldgrid 2 Wp Super Cache, W3 Total Cache 2024-11-21 9.8 Critical
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability