Search
Search Results (20782 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-15780 | 1 Strategy11 | 1 Formidable Form Builder | 2024-11-21 | 9.8 Critical |
| The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. | ||||
| CVE-2019-15779 | 1 Quadlayers | 1 Wp Social Feed Gallery | 2024-11-21 | N/A |
| The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete. | ||||
| CVE-2019-15778 | 1 Getwooplugins | 1 Additional Variation Images For Woocommerce | 2024-11-21 | N/A |
| The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS. | ||||
| CVE-2019-15777 | 1 Shapepress | 1 Wp Dsgvo Tools | 2024-11-21 | N/A |
| The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS. | ||||
| CVE-2019-15776 | 1 Webcraftic | 1 Simple 301 Redirects-addon-bulk Uploader | 2024-11-21 | N/A |
| The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file. | ||||
| CVE-2019-15775 | 1 Learning Courses Project | 1 Learning Courses | 2024-11-21 | N/A |
| The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | ||||
| CVE-2019-15774 | 1 Booking Project | 1 Booking | 2024-11-21 | N/A |
| The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | ||||
| CVE-2019-15773 | 1 Travel Management Project | 1 Travel Management | 2024-11-21 | N/A |
| The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | ||||
| CVE-2019-15772 | 1 Donations Project | 1 Donations | 2024-11-21 | N/A |
| The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | ||||
| CVE-2019-15771 | 1 Components For Wp Bakery Page Builder Project | 1 Components For Wp Bakery Page Builder | 2024-11-21 | N/A |
| The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | ||||
| CVE-2019-15770 | 1 Hallme | 1 Woocommerce Address Book | 2024-11-21 | N/A |
| The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. | ||||
| CVE-2019-15769 | 1 Haktansuren | 1 Handl Utm Grabber | 2024-11-21 | N/A |
| The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. | ||||
| CVE-2019-15713 | 1 My Calendar Project | 1 My Calendar | 2024-11-21 | N/A |
| The my-calendar plugin before 3.1.10 for WordPress has XSS. | ||||
| CVE-2019-15660 | 1 Butlerblog | 1 Wp-members | 2024-11-21 | N/A |
| The wp-members plugin before 3.2.8 for WordPress has CSRF. | ||||
| CVE-2019-15659 | 1 Genetechsolutions | 1 Pie Register | 2024-11-21 | N/A |
| The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. | ||||
| CVE-2019-15650 | 1 Easyupdatesmanager | 1 Easy Updates Manager | 2024-11-21 | N/A |
| The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error. | ||||
| CVE-2019-15649 | 1 Elearningfreak | 1 Insert Or Embed Articulate Content | 2024-11-21 | N/A |
| The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload. | ||||
| CVE-2019-15648 | 1 Elearningfreak | 1 Insert Or Embed Articulate Content | 2024-11-21 | N/A |
| The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. | ||||
| CVE-2019-15647 | 1 Groundhogg | 1 Groundhogg | 2024-11-21 | N/A |
| The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution. | ||||
| CVE-2019-15646 | 1 Carrcommunications | 1 Rsvpmaker | 2024-11-21 | N/A |
| The rsvpmaker plugin before 6.2 for WordPress has SQL injection. | ||||