Latest CVE Feed
-
5.9
MEDIUMCVE-2021-39359
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.... Read more
- EPSS Score: %0.27
- Published: Aug. 22, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-39358
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.... Read more
- EPSS Score: %0.22
- Published: Aug. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39357
The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the ~/class.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in vers... Read more
Affected Products : leaky_paywall- EPSS Score: %0.45
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39356
The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via several parameters that are echo'd out via the ~/templates/settings.php file which allowed attackers with administrativ... Read more
Affected Products : content_staging- EPSS Score: %0.57
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39355
The Indeed Job Importer WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/indeed-job-importer/trunk/indeed-job-importer.php file which allowed attacker... Read more
Affected Products : indeed-job-importer- EPSS Score: %0.57
- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39353
The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary we... Read more
Affected Products : easy_registration_forms- EPSS Score: %0.11
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-39352
The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes... Read more
Affected Products : catch_themes_demo_import- EPSS Score: %77.76
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39349
The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-author-bio-box-admin.php file which allowed attackers with ad... Read more
Affected Products : author_bio_box- EPSS Score: %0.91
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39348
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access... Read more
Affected Products : learnpress- EPSS Score: %0.45
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39347
The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes/admin/class-wc-stripe-admin-user-edit.php file that makes it possible for attackers to configure their account to use other site users... Read more
Affected Products : stripe_for_woocommerce- EPSS Score: %0.14
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-39346
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attack... Read more
Affected Products : easy_google_maps- EPSS Score: %0.43
- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39345
The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/wp-hal.php file which allowed attackers with administrative user access to inject arbitrary w... Read more
Affected Products : hal- EPSS Score: %0.41
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39344
The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/class-kjm-admin-notices-admin.php file which allowed attackers with admin... Read more
Affected Products : kjm_admin_notices- EPSS Score: %0.57
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39342
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects vers... Read more
Affected Products : financial- EPSS Score: %0.13
- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-39341
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to ex... Read more
Affected Products : optinmonster- EPSS Score: %27.20
- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-39340
The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with admini... Read more
Affected Products : notification- EPSS Score: %0.47
- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-39339
The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file due to a user-supplied URL request value that gets called by a curl requests. This affects versions up to, and including, 1.8.0.... Read more
Affected Products : telefication- EPSS Score: %0.22
- Published: Sep. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39338
The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowed attackers with administrative use... Read more
Affected Products : mybb_cross-poster- EPSS Score: %0.41
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39337
The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/jobs_function.php file which allowed attackers with administrative user access t... Read more
Affected Products : job-portal- EPSS Score: %0.41
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39336
The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject... Read more
Affected Products : job_manager- EPSS Score: %0.45
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024