Total
292450 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-38329 | 1 Dj Emailpublish Project | 1 Dj Emailpublish | 2025-05-02 | 6.1 Medium |
The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/dj-email-publish.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.7.2. | ||||
CVE-2022-41679 | 1 Formalms | 1 Formalms | 2025-05-02 | 4.7 Medium |
Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the “back_url” parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the user´s cookies in order to log in to the application. | ||||
CVE-2021-38348 | 1 Advance Search Project | 1 Advance Search | 2025-05-02 | 6.1 Medium |
The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in the ~/inc/admin/views/html-advance-search-admin-options.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.2. | ||||
CVE-2021-38326 | 1 Wpleet | 1 Post Title Counter | 2025-05-02 | 6.1 Medium |
The Post Title Counter WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the notice parameter found in the ~/post-title-counter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1. | ||||
CVE-2020-36084 | 1 Jkev | 1 Responsive E-learning System | 2025-05-02 | 9.8 Critical |
SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field. | ||||
CVE-2025-22928 | 1 Os4ed | 1 Opensis | 2025-05-02 | 9.8 Critical |
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php. | ||||
CVE-2021-38353 | 1 Webodid | 1 Dropdown And Scrollable Text | 2025-05-02 | 6.1 Medium |
The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0. | ||||
CVE-2024-55496 | 1 1000projects | 1 Bookstore Management System | 2025-05-02 | 9.1 Critical |
A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection. | ||||
CVE-2024-48580 | 2 Mayurik, Php | 2 Best Courier Management System, Best Courier Management System | 2025-05-02 | 9.8 Critical |
SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request. | ||||
CVE-2021-38349 | 1 Techastha | 1 Integration Of Moneybird For Woocommerce | 2025-05-02 | 6.1 Medium |
The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1. | ||||
CVE-2024-48259 | 1 Magicbug | 1 Cloudlog | 2025-05-02 | 7.3 High |
Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign. | ||||
CVE-2021-38340 | 1 Wordpress Simple Shop Project | 1 Wordpress Simple Shop | 2025-05-02 | 6.1 Medium |
The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2. | ||||
CVE-2024-24407 | 1 Mayurik | 1 Best Courier Management System | 2025-05-02 | 5.3 Medium |
SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component. | ||||
CVE-2021-38341 | 1 Dreamfoxmedia | 1 Woocommerce Payment Gateway Per Category | 2025-05-02 | 6.1 Medium |
The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.10. | ||||
CVE-2024-22983 | 1 Projectworlds | 2 Visitor Management System, Visitor Management System In Php | 2025-05-02 | 8.1 High |
SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint. | ||||
CVE-2021-38334 | 1 Amazingweb | 1 Wp-design-maps-places | 2025-05-02 | 6.1 Medium |
The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter found in the ~/wpdmp-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2. | ||||
CVE-2021-38330 | 1 Tromit | 1 Yabp | 2025-05-02 | 6.1 Medium |
The Yet Another bol.com Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/yabp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4. | ||||
CVE-2021-38337 | 1 Carrcommunications | 1 Rsvpmaker Excel | 2025-05-02 | 6.1 Medium |
The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1. | ||||
CVE-2021-38332 | 1 Ops-robots-txt Project | 1 Ops-robots-txt | 2025-05-02 | 6.1 Medium |
The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1. | ||||
CVE-2021-38335 | 1 Wiseagent | 1 Wise Agent Capture Forms | 2025-05-02 | 6.1 Medium |
The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/WiseAgentCaptureForm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0. |