Lucene search

K

Website Security Vulnerabilities

cve
cve

CVE-2024-2267

A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0 and classified as problematic. This issue affects some unknown processing of the file /shop.php. The manipulation of the argument product_price leads to business logic errors. The attack may be initiated remotely. The exploit...

4.3CVSS

4.7AI Score

0.0004EPSS

2024-03-07 10:15 PM
29
cve
cve

CVE-2024-2127

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

6.4CVSS

5.8AI Score

0.0004EPSS

2024-03-07 08:15 PM
30
cve
cve

CVE-2024-1468

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with...

8.8CVSS

8.8AI Score

0.0004EPSS

2024-02-29 04:15 AM
70
cve
cve

CVE-2024-0506

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping.....

6.4CVSS

6.3AI Score

0.0004EPSS

2024-02-29 01:43 AM
43
cve
cve

CVE-2023-7108

A vulnerability classified as problematic has been found in code-projects E-Commerce Website 1.0. This affects an unknown part of the file user_signup.php. The manipulation of the argument firstname with the input leads to cross site scripting. It is possible to initiate the attack remotely. The...

4.3CVSS

4.4AI Score

0.0004EPSS

2024-02-29 01:42 AM
15
cve
cve

CVE-2023-7105

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been classified as critical. Affected is an unknown function of the file index_search.php. The manipulation of the argument search leads to sql injection. It is possible to launch the attack remotely. The exploit has been...

4.7CVSS

5.3AI Score

0.0004EPSS

2024-02-29 01:42 AM
8
cve
cve

CVE-2023-7106

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file product_details.php?prod_id=11. The manipulation of the argument prod_id leads to sql injection. The attack can be launched...

6.3CVSS

6.8AI Score

0.0004EPSS

2024-02-29 01:42 AM
5
cve
cve

CVE-2023-7107

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user_signup.php. The manipulation of the argument firstname/middlename/email/address/contact/username leads to sql injection. The...

7.3CVSS

7.5AI Score

0.0004EPSS

2024-02-29 01:42 AM
6
cve
cve

CVE-2024-1817

A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the function dmlogin of the file indexDM_load.php of the component Cookie Handler. The manipulation of the argument is_admin with the input y.....

7.3CVSS

7.2AI Score

0.0004EPSS

2024-02-23 02:15 PM
49
cve
cve

CVE-2024-1590

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This...

4.6CVSS

5AI Score

0.0004EPSS

2024-02-23 10:15 AM
49
cve
cve

CVE-2024-1072

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21.....

8.2CVSS

7.7AI Score

0.001EPSS

2024-02-05 10:16 PM
14
cve
cve

CVE-2023-6684

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height' user supplied attribute. This makes it...

6.4CVSS

5.2AI Score

0.001EPSS

2024-01-11 09:15 AM
43
cve
cve

CVE-2023-6505

The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export...

7.5CVSS

7.5AI Score

0.003EPSS

2024-01-08 07:15 PM
64
cve
cve

CVE-2023-50867

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the...

9.8CVSS

9.9AI Score

0.001EPSS

2024-01-04 03:15 PM
10
cve
cve

CVE-2023-50866

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the...

9.8CVSS

9.9AI Score

0.001EPSS

2024-01-04 03:15 PM
8
cve
cve

CVE-2023-50864

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the...

9.8CVSS

9.9AI Score

0.001EPSS

2024-01-04 03:15 PM
12
cve
cve

CVE-2023-50865

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and they are sent unfiltered to the...

9.8CVSS

9.9AI Score

0.001EPSS

2024-01-04 03:15 PM
13
cve
cve

CVE-2023-50863

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and they are sent unfiltered to the...

9.8CVSS

9.9AI Score

0.001EPSS

2024-01-04 03:15 PM
10
cve
cve

CVE-2023-50862

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the...

9.8CVSS

9.9AI Score

0.001EPSS

2024-01-04 03:15 PM
10
cve
cve

CVE-2023-6738

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input...

5.4CVSS

5.2AI Score

0.001EPSS

2024-01-04 04:15 AM
16
cve
cve

CVE-2023-6436

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template: through...

9.8CVSS

9.7AI Score

0.001EPSS

2024-01-02 01:15 PM
12
cve
cve

CVE-2023-50893

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution Impreza – WordPress Website and WooCommerce Builder allows Reflected XSS.This issue affects Impreza – WordPress Website and WooCommerce Builder: from n/a through...

7.1CVSS

6.5AI Score

0.0005EPSS

2023-12-29 12:15 PM
47
cve
cve

CVE-2023-33209

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrawlSpider SEO Change Monitor – Track Website Changes.This issue affects SEO Change Monitor – Track Website Changes: from n/a through...

8.5CVSS

8.4AI Score

0.001EPSS

2023-12-20 04:15 PM
14
cve
cve

CVE-2023-6896

A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument search with the input sy2ap%22%3e%3cscript%3ealert(1)%3c%2fscript%3etkxh1 leads to cross site scripting. The...

6.1CVSS

6AI Score

0.001EPSS

2023-12-17 10:15 AM
18
cve
cve

CVE-2023-48049

A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py...

9.8CVSS

9.8AI Score

0.001EPSS

2023-12-15 12:15 AM
5
cve
cve

CVE-2023-47505

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through...

6.5CVSS

5.6AI Score

0.0004EPSS

2023-11-30 12:15 PM
80
cve
cve

CVE-2023-5715

The Website Optimization – Plerdy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tracking code settings in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

4.8CVSS

5AI Score

0.001EPSS

2023-11-22 04:15 PM
63
cve
cve

CVE-2023-27633

Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Customify – Intuitive Website Styling plugin <= 2.10.4...

8.8CVSS

8.7AI Score

0.001EPSS

2023-11-22 02:15 PM
7
cve
cve

CVE-2023-47544

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.12...

7.1CVSS

5.7AI Score

0.0005EPSS

2023-11-14 09:15 PM
11
cve
cve

CVE-2023-26543

Cross-Site Request Forgery (CSRF) vulnerability in Aleksandr Guidrevitch WP Meteor Website Speed Optimization Addon plugin <= 3.1.4...

8.8CVSS

8.7AI Score

0.001EPSS

2023-11-13 01:15 AM
13
cve
cve

CVE-2023-5919

A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched...

7.2CVSS

7AI Score

0.001EPSS

2023-11-02 02:15 PM
22
cve
cve

CVE-2023-5049

The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rafflepress' and 'rafflepress_gutenberg' shortcode in versions up to, and including, 1.12.0 due to insufficient input sanitization and output escaping on 'giframe' user supplied...

6.4CVSS

5.2AI Score

0.001EPSS

2023-10-30 02:15 PM
42
cve
cve

CVE-2023-4975

The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.15.13.1. This is due to missing or incorrect nonce validation on functionality in the builder.php file. This makes it possible for unauthenticated attackers to...

4.3CVSS

4.5AI Score

0.001EPSS

2023-10-20 07:15 AM
9
cve
cve

CVE-2023-44245

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Leap Contractor Contact Form Website to Workflow Tool plugin <= 4.0.0...

7.1CVSS

6AI Score

0.0005EPSS

2023-10-02 10:15 AM
20
cve
cve

CVE-2023-5014

A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to....

9.8CVSS

9.7AI Score

0.001EPSS

2023-09-17 01:15 AM
17
cve
cve

CVE-2023-37393

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3...

7.1CVSS

4.9AI Score

0.0004EPSS

2023-09-04 11:15 AM
20
cve
cve

CVE-2023-39115

install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG...

9.8CVSS

8.7AI Score

0.006EPSS

2023-08-16 03:15 PM
12
cve
cve

CVE-2022-4953

The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious...

6.1CVSS

6AI Score

0.002EPSS

2023-08-14 08:15 PM
97
cve
cve

CVE-2023-3642

A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /VacationRentalWebsite/property/8/ad-has-principes/ of the component HTTP POST Request Handler. The manipulation of the argument...

6.1CVSS

6AI Score

0.001EPSS

2023-07-12 05:15 PM
12
cve
cve

CVE-2023-22673

Cross-Site Request Forgery (CSRF) vulnerability in MageNet Website Monetization by MageNet plugin <= 1.0.29.1...

8.8CVSS

8.7AI Score

0.001EPSS

2023-07-10 04:15 PM
7
cve
cve

CVE-2023-3534

A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file check_availability.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has...

7.5CVSS

7.9AI Score

0.001EPSS

2023-07-07 12:15 PM
11
cve
cve

CVE-2023-3503

A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been...

8.8CVSS

8.7AI Score

0.001EPSS

2023-07-04 03:15 PM
115
cve
cve

CVE-2023-3502

A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unknown function of the file search-result.php. The manipulation of the argument product leads to sql injection. It is possible to launch the attack remotely. The exploit has been...

7.5CVSS

7.9AI Score

0.001EPSS

2023-07-04 02:15 PM
13
cve
cve

CVE-2023-36817

tktchurch/website contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase. If an unauthorized...

9.1CVSS

9.1AI Score

0.001EPSS

2023-07-03 06:15 PM
2375
cve
cve

CVE-2023-3458

A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file forgot-password.php. The manipulation of the argument contact leads to sql injection. The attack can be launched remotely. The.....

9.8CVSS

9.7AI Score

0.001EPSS

2023-06-29 02:15 PM
11
cve
cve

CVE-2023-3457

A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been...

9.8CVSS

9.7AI Score

0.001EPSS

2023-06-29 02:15 PM
9
cve
cve

CVE-2023-3124

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update...

8.8CVSS

8.3AI Score

0.001EPSS

2023-06-07 02:15 AM
143
cve
cve

CVE-2020-36722

The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's...

5.5CVSS

4.9AI Score

0.001EPSS

2023-06-07 02:15 AM
13
cve
cve

CVE-2020-36703

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will...

6.4CVSS

5AI Score

0.001EPSS

2023-06-07 02:15 AM
9
cve
cve

CVE-2020-36711

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers, and above, to inject arbitrary web...

6.4CVSS

5.2AI Score

0.001EPSS

2023-06-07 02:15 AM
12
Total number of security vulnerabilities272