CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12767
3.5 LOW

The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts

May 15, 2025
CVE-2024-12750
4.3 MEDIUM

The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-12743
4.8 MEDIUM

The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-12739
4.8 MEDIUM

The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-12735
7.2 HIGH

The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and …

May 15, 2025
CVE-2024-12734
6.1 MEDIUM

The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it …

May 15, 2025
CVE-2024-12733
6.1 MEDIUM

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-12732
6.1 MEDIUM

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-12726
6.1 MEDIUM

The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-12725
6.1 MEDIUM

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 15, 2025
CVE-2024-12724
6.1 MEDIUM

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

May 15, 2025
CVE-2024-12722
5.4 MEDIUM

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back …

May 15, 2025
CVE-2024-12716
4.8 MEDIUM

The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-12680
4.8 MEDIUM

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-12679
4.8 MEDIUM

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-12301
6.5 MEDIUM

The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users …

May 15, 2025
CVE-2024-12282
6.1 MEDIUM

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2024-11843
4.8 MEDIUM

The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-11719
6.1 MEDIUM

The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2024-11718
5.4 MEDIUM

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor …

May 15, 2025
CVE-2024-11502
5.4 MEDIUM

The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a …

May 15, 2025
CVE-2024-11373
4.3 MEDIUM

The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-11372
7.2 HIGH

The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform …

May 15, 2025
CVE-2024-11269
7.2 HIGH

The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform …

May 15, 2025
CVE-2024-11267
8.8 HIGH

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with …

May 15, 2025
CVE-2024-11266
4.8 MEDIUM

The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-11221
4.8 MEDIUM

The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege …

May 15, 2025
CVE-2024-11190
4.8 MEDIUM

The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-11189
4.8 MEDIUM

The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users …

May 15, 2025
CVE-2024-11141
6.1 MEDIUM

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers …

May 15, 2025
CVE-2024-11140
3.5 LOW

The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow …

May 15, 2025
CVE-2024-11109
4.8 MEDIUM

The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-10818
5.4 MEDIUM

The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

May 15, 2025
CVE-2024-10677
4.3 MEDIUM

The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

May 15, 2025
CVE-2024-10639
4.8 MEDIUM

The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-10634
4.3 MEDIUM

The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make …

May 15, 2025
CVE-2024-10632
4.8 MEDIUM

The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin …

May 15, 2025
CVE-2024-10631
6.5 MEDIUM

The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back …

May 15, 2025
CVE-2024-10504
5.4 MEDIUM

The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the …

May 15, 2025
CVE-2024-10475
4.8 MEDIUM

The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow …

May 15, 2025
CVE-2024-10362
4.8 MEDIUM

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow …

May 15, 2025
CVE-2024-10149
4.8 MEDIUM

The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-10145
4.8 MEDIUM

The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-10144
4.8 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its settings, which could allow …

May 15, 2025
CVE-2024-10143
4.8 MEDIUM

The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its settings, which could allow high …

May 15, 2025
CVE-2024-10107
4.8 MEDIUM

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users …

May 15, 2025
CVE-2024-10098
2.7 LOW

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information …

May 15, 2025
CVE-2024-10076
5.9 MEDIUM

The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their …

May 15, 2025
CVE-2024-10075
5.6 MEDIUM

The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could …

May 15, 2025
CVE-2024-10054
4.8 MEDIUM

The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.