CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2021-24972

    Last Modified: 21 Nov 2024

    The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 13 Dec 2021
    7.2
    High

    CVE-2021-24970

    Last Modified: 21 Nov 2024

    The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue

    Published: 13 Dec 2021
    6.1
    Medium

    CVE-2021-24955

    Last Modified: 21 Nov 2024

    The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

    Published: 13 Dec 2021
    6.1
    Medium

    CVE-2021-24954

    Last Modified: 21 Nov 2024

    The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-24951

    Last Modified: 21 Nov 2024

    The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-24946

    Last Modified: 21 Nov 2024

    The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

    Published: 13 Dec 2021
    8
    High

    CVE-2021-24945

    Last Modified: 21 Nov 2024

    The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

    Published: 13 Dec 2021
    6.1
    Medium

    CVE-2021-24932

    Last Modified: 21 Nov 2024

    The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.

    Published: 13 Dec 2021
    6.1
    Medium

    CVE-2021-24925

    Last Modified: 21 Nov 2024

    The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

    Published: 13 Dec 2021
    9
    Critical

    CVE-2021-24922

    Last Modified: 21 Nov 2024

    The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks

    Published: 13 Dec 2021
    4.8
    Medium

    CVE-2021-24896

    Last Modified: 21 Nov 2024

    The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2021-24872

    Last Modified: 21 Nov 2024

    The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.

    Published: 13 Dec 2021
    5.4
    Medium

    CVE-2021-24871

    Last Modified: 21 Nov 2024

    The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-24863

    Last Modified: 16 Jan 2026

    The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection

    Published: 13 Dec 2021
    7.2
    High

    CVE-2021-24861

    Last Modified: 21 Nov 2024

    The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-24859

    Last Modified: 21 Nov 2024

    The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-24857

    Last Modified: 21 Nov 2024

    The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.

    Published: 13 Dec 2021
    5.4
    Medium

    CVE-2021-24855

    Last Modified: 21 Nov 2024

    The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

    Published: 13 Dec 2021
    8.8
    High

    CVE-2021-24848

    Last Modified: 21 Nov 2024

    The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2021-24845

    Last Modified: 21 Nov 2024

    The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor can gain access to content they are not supposed to.

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-24836

    Last Modified: 21 Nov 2024

    The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-24819

    Last Modified: 21 Nov 2024

    The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-24818

    Last Modified: 21 Nov 2024

    The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make a logged in admin change them, which could make the blog unstable by setting low values

    Published: 13 Dec 2021
    5.4
    Medium

    CVE-2021-24817

    Last Modified: 21 Nov 2024

    The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2021-24795

    Last Modified: 21 Nov 2024

    The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.

    Published: 13 Dec 2021
    6.1
    Medium

    CVE-2021-24792

    Last Modified: 21 Nov 2024

    The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template and lead to Stored Cross-Site Scripting issues.

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-24790

    Last Modified: 21 Nov 2024

    The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2021-24784

    Last Modified: 21 Nov 2024

    The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.

    Published: 13 Dec 2021
    4.8
    Medium

    CVE-2021-24782

    Last Modified: 21 Nov 2024

    The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-24780

    Last Modified: 21 Nov 2024

    The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and give access to the export feature to any role such as subscriber. Subscriber users would then be able to export an arbitrary post/page (such as private and password protected) via a direct URL

    Published: 13 Dec 2021
    4.8
    Medium

    CVE-2021-24771

    Last Modified: 21 Nov 2024

    The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the "Quotes list" even when the unfiltered_html capability is disallowed

    Published: 13 Dec 2021
    6.1
    Medium

    CVE-2021-24756

    Last Modified: 21 Nov 2024

    The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.

    Published: 13 Dec 2021
    7.2
    High

    CVE-2021-24747

    Last Modified: 21 Nov 2024

    The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections.

    Published: 13 Dec 2021
    4.8
    Medium

    CVE-2021-24705

    Last Modified: 21 Nov 2024

    The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape some of its settings as well as form fields before outputting them in attributes. This could allow attackers to make a logged in admin edit arbitrary forms with Cross-Site Scripting payloads in them

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2021-20867

    Last Modified: 21 Nov 2024

    Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2021-20866

    Last Modified: 21 Nov 2024

    Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-20865

    Last Modified: 21 Nov 2024

    Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.

    Published: 13 Dec 2021
    7.2
    High

    CVE-2021-44154

    Last Modified: 30 Apr 2025

    An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_opt, which will then be triggered when running the diagnostics (via /goform/diagnostics_doit), resulting in a buffer overflow.

    Published: 13 Dec 2021
    7.2
    High

    CVE-2021-44153

    Last Modified: 30 Apr 2025

    An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable an option to run arbitrary executables, as demonstrated by an ISV demo "C:\Windows\System32\calc.exe" entry. An attacker can exploit this to run a malicious binary on startup, or when triggering the Reread/Restart Servers function on the webserver. (Exploitation does not require CVE-2018-15573, because the license file is meant to be changed in the application.)

    Published: 13 Dec 2021
    4.9
    Medium

    CVE-2021-40858

    Last Modified: 21 Nov 2024

    Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

    Published: 13 Dec 2021
    8.8
    High

    CVE-2021-40857

    Last Modified: 21 Nov 2024

    Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-40856

    Last Modified: 21 Nov 2024

    Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.

    Published: 13 Dec 2021
    5.3
    Medium

    CVE-2021-44848

    Last Modified: 21 Nov 2024

    In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2018-25021

    Last Modified: 21 Nov 2024

    The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-44847

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.

    Published: 13 Dec 2021
    3.1
    Low

    CVE-2018-25022

    Last Modified: 21 Nov 2024

    The Onion module in toxcore before 0.2.2 doesn't restrict which packets can be onion-routed, which allows a remote attacker to discover a target user's IP address (when knowing only their Tox Id) by positioning themselves close to target's Tox Id in the DHT for the target to establish an onion connection with the attacker, guessing the target's DHT public key and creating a DHT node with public key close to it, and finally onion-routing a NAT Ping Request to the target, requesting it to ping the just created DHT node.

    Published: 13 Dec 2021
    5.3
    Medium

    CVE-2021-44155

    Last Modified: 30 Apr 2025

    An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an attacker to enumerate valid users.

    Published: 13 Dec 2021
    8.1
    High

    CVE-2022-23451

    Last Modified: 21 Nov 2024

    An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

    Published: 13 Dec 2021
    4.9
    Medium

    CVE-2022-23452

    Last Modified: 21 Nov 2024

    An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-44151

    Last Modified: 30 Apr 2025

    An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version appears to have 8 characters). An attacker can obtain the static part of the cookie (cookie name) by first making a request to any page on the application (e.g., /goforms/menu) and saving the name of the cookie sent with the response. The attacker can then use the name of the cookie and try to request that same page, setting a random value for the cookie. If any user has an active session, the page should return with the authorized content, when a valid cookie value is hit.

    Published: 13 Dec 2021