|
196141
|
7.2 |
HIGH
Network
|
nimble3
|
m-vslider
|
The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users…
|
-
|
CVE-2021-24557
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196142
|
6.1 |
MEDIUM
Network
|
email-subscriber_project
|
email-subscriber
|
The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sanitise, validate and escape the submitted subscribe_email and subscribe_name POST…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24556
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196143
|
8.8 |
HIGH
Network
|
roosty
|
diary-availability-calendar
|
The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or…
|
-
|
CVE-2021-24555
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196144
|
7.2 |
HIGH
Network
|
freelancetoindia
|
paytm-pay
|
The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authent…
|
-
|
CVE-2021-24554
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196145
|
7.2 |
HIGH
Network
|
timeline_calendar_project
|
timeline_calendar
|
The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL…
|
-
|
CVE-2021-24553
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196146
|
7.2 |
HIGH
Network
|
simple_events_calendar_project
|
simple_events_calendar
|
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an auth…
|
-
|
CVE-2021-24552
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196147
|
9.8 |
CRITICAL
Network
|
edit_comments_project
|
edit_comments
|
The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue
|
-
|
CVE-2021-24551
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196148
|
7.2 |
HIGH
Network
|
broken_link_manager_project
|
broken_link_manager
|
The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an aut…
|
-
|
CVE-2021-24550
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196149
|
4.9 |
MEDIUM
Network
|
aceide_project
|
aceide
|
The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths before using it in various actions, such as to read arbitrary files from the s…
|
-
|
CVE-2021-24549
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196150
|
5.4 |
MEDIUM
Network
|
kn_fix_your_title_project
|
kn_fix_your_title
|
The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.
|
-
|
CVE-2021-24547
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|