|
196061
|
6.1 |
MEDIUM
Network
|
purethemes
|
listeo
|
The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues
|
-
|
CVE-2021-24317
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196062
|
6.1 |
MEDIUM
Network
|
wowthemes
|
mediumish
|
The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.
|
-
|
CVE-2021-24316
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196063
|
5.4 |
MEDIUM
Network
|
goprayer
|
wp_prayer
|
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by us…
|
-
|
CVE-2021-24313
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196064
|
7.2 |
HIGH
Network
|
automattic
|
wp_super_cache
|
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 resul…
|
CWE-78
OS Command
|
CVE-2021-24312
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196065
|
8.8 |
HIGH
Network
|
external_media_project
|
external_media
|
The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.
|
-
|
CVE-2021-24311
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196066
|
4.8 |
MEDIUM
Network
|
10web
|
photo_gallery
|
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in …
|
-
|
CVE-2021-24310
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196067
|
5.4 |
MEDIUM
Network
|
weekly_schedule_project
|
weekly_schedule
|
The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags …
|
-
|
CVE-2021-24309
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196068
|
7.5 |
HIGH
Network
|
apache
|
wicket
|
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is no…
|
CWE-200
Information Exposure
|
CVE-2021-23937
|
2024-11-21 14:52 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196069
|
4.8 |
MEDIUM
Network
|
autoptimize
|
autoptimize
|
The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-…
|
-
|
CVE-2021-24332
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196070
|
5.4 |
MEDIUM
Network
|
lifterlms
|
lifterlms
|
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when ou…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24308
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|