Search Results (20778 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-5293 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 N/A
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
CVE-2018-5292 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 N/A
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
CVE-2018-5291 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 N/A
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
CVE-2018-5290 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 N/A
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
CVE-2018-5289 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 N/A
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
CVE-2018-5288 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 N/A
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
CVE-2018-5287 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 N/A
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
CVE-2018-5286 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 N/A
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
CVE-2018-5285 1 Wpscoop 1 Imageinject 2024-11-21 N/A
The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php.
CVE-2018-5284 1 Wpscoop 1 Imageinject 2024-11-21 N/A
The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.
CVE-2018-5214 1 Add Link To Facebook Project 1 Add Link To Facebook 2024-11-21 N/A
The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fb_facebook_id parameter to wp-admin/profile.php.
CVE-2018-5213 1 Simple Download Monitor Project 1 Simple Download Monitor 2024-11-21 N/A
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
CVE-2018-5212 1 Simple Download Monitor Project 1 Simple Download Monitor 2024-11-21 N/A
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
CVE-2018-3811 1 Oturia 1 Smart Google Code Inserter 2024-11-21 N/A
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] variable before passing it as input into the SQL query.
CVE-2018-3810 1 Oturia 1 Smart Google Code Inserter 2024-11-21 N/A
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.
CVE-2018-25019 1 Learndash 1 Learndash 2024-11-21 7.5 High
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server
CVE-2018-21014 1 Buddyboss 1 Buddymoss Media 2024-11-21 5.4 Medium
The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
CVE-2018-21013 1 Upperthemes 1 Swape 2024-11-21 9.8 Critical
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.
CVE-2018-21012 1 Vsourz 1 Cf7 Invisible Recaptcha 2024-11-21 6.1 Medium
The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.
CVE-2018-21011 1 Wpcharitable 1 Charitable 2024-11-21 7.5 High
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.