|
196331
|
6.1 |
MEDIUM
Network
|
tielabs
|
jannah
|
The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cros…
|
-
|
CVE-2021-24364
|
2024-11-21 14:52 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196332
|
9.8 |
CRITICAL
Network
|
ayecode
|
location_manager
|
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL stat…
|
-
|
CVE-2021-24361
|
2024-11-21 14:52 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196333
|
5.4 |
MEDIUM
Network
|
podsfoundation
|
pods
|
The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field par…
|
-
|
CVE-2021-24339
|
2024-11-21 14:52 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196334
|
5.4 |
MEDIUM
Network
|
podsfoundation
|
pods
|
The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field…
|
-
|
CVE-2021-24338
|
2024-11-21 14:52 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196335
|
6.1 |
MEDIUM
Network
|
expresstech
|
quiz_and_survey_master
|
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading …
|
-
|
CVE-2021-24368
|
2024-11-21 14:52 |
2021-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196336
|
9.8 |
CRITICAL
Network
|
facebook
|
hermes
|
A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScri…
|
CWE-416
Use After Free
|
CVE-2021-24037
|
2024-11-21 14:52 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196337
|
5.4 |
MEDIUM
Network
|
nextendweb
|
smart_slider
|
The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, o…
|
-
|
CVE-2021-24382
|
2024-11-21 14:52 |
2021-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196338
|
6.5 |
MEDIUM
Network
|
kohsei-works
|
yes\/no_chart
|
The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL In…
|
-
|
CVE-2021-24360
|
2024-11-21 14:52 |
2021-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196339
|
6.1 |
MEDIUM
Network
|
posimyth
|
the_plus_addons_for_elementor
|
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Red…
|
-
|
CVE-2021-24358
|
2024-11-21 14:52 |
2021-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196340
|
5.4 |
MEDIUM
Network
|
fooplugins
|
foogallery
|
In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output…
|
-
|
CVE-2021-24357
|
2024-11-21 14:52 |
2021-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|