CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Ayecode Remove filter Clear all
CVE-2026-85705 HIGH

Location Manager <= 2.3.38 - Unauthenticated SQL Injection via 'latitude' and 'longitude' REST API Parameters

CVSS 7.5 EPSS 0.46% Sep 18, 2026
CVE-2025-52746 HIGH

WordPress Restaurante theme <= 3.0.7 - Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.30% Jan 22, 2026
CVE-2025-6200 MEDIUM

GeoDirectory < 2.8.120 - Contributor+ Stored XSS

CVSS 5.9 EPSS 0.23% Jul 11, 2025
CVE-2025-24673 MEDIUM

WordPress Ketchup Shortcodes Plugin <= 0.1.2 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.35% Jan 24, 2025
CVE-2024-13590 MEDIUM

Ketchup Shortcodes <= 0.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVSS 6.4 EPSS 0.24% Jan 22, 2025
CVE-2024-56259 MEDIUM

WordPress GeoDirectory plugin <= 2.3.84 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.33% Jan 2, 2025
CVE-2024-56255 MEDIUM

WordPress AyeCode Connect plugin <= 1.3.8 - Broken Access Control vulnerability

CVSS 4.3 EPSS 0.29% Jan 2, 2025
CVE-2024-43277 MEDIUM

WordPress UsersWP plugin <= 1.2.15 - Broken Access Control vulnerability

CVSS 5.3 EPSS 0.40% Nov 1, 2024
CVE-2024-43973 HIGH

WordPress GetPaid plugin <= 2.8.11 - Broken Access Control vulnerability

CVSS 8.8 EPSS 0.47% Nov 1, 2024
CVE-2024-43981 HIGH

WordPress GeoDirectory plugin <= 2.3.70 - Broken Access Control vulnerability

CVSS 8.8 EPSS 0.42% Nov 1, 2024
CVE-2024-50437 MEDIUM

WordPress GeoDirectory plugin <= 2.3.80 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.26% Oct 28, 2024
CVE-2024-43145 HIGH

WordPress GeoDirectory plugin <= 2.3.61 - SQL Injection vulnerability

CVSS 8.8 EPSS 0.44% Aug 18, 2024
CVE-2024-6477 HIGH

UsersWP < 1.2.12 - Users Information Disclosure

CVSS 7.5 EPSS 0.57% Aug 3, 2024
CVE-2024-6265 CRITICAL

UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sor…

CVSS 9.8 EPSS 2.38% Jun 29, 2024
CVE-2024-3732 MEDIUM

GeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single…

CVSS 6.4 EPSS 0.32% Apr 23, 2024
CVE-2024-31936 MEDIUM

WordPress UsersWP plugin < 1.2.6 - Cross Site Request Forgery (CSRF) vulnerability

CVSS 5.4 EPSS 0.20% Apr 11, 2024
CVE-2024-2423 MEDIUM

UsersWP <= 1.2.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

CVSS 6.4 EPSS 0.45% Apr 9, 2024
CVE-2023-50845 HIGH

WordPress GeoDirectory Plugin <= 2.3.28 is vulnerable to SQL Injection

CVSS 7.6 EPSS 0.54% Dec 28, 2023
CVE-2022-47442 HIGH

WordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV Injection

CVSS 8.8 EPSS 0.68% Nov 7, 2023
CVE-2023-2813 MEDIUM

Multiple Themes - Reflected XSS

CVSS 6.1 EPSS 1.01% Sep 4, 2023
CVE-2022-4775 MEDIUM

GeoDirectory < 2.2.22 - Contributor+ Stored XSS via Shortcode

CVSS 5.4 EPSS 0.47% Jan 23, 2023
CVE-2022-29453 MEDIUM

WordPress API KEY for Google Maps plugin <= 1.2.1 - CSRF vulnerability leading to Google Maps API key update

CVSS 5.4 EPSS 0.43% Jun 15, 2022
CVE-2022-0442 MEDIUM

UsersWP < 1.2.3.1 - Subscriber+ User Avatar Override

CVSS 4.3 EPSS 0.65% Mar 7, 2022
CVE-2021-24720 MEDIUM

GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)

CVSS 5.4 EPSS 0.88% Oct 11, 2021
CVE-2021-24369 MEDIUM

GetPaid < 2.3.4 - Authenticated Stored XSS

CVSS 5.4 EPSS 0.62% Jun 21, 2021

Showing 1 to 25 CVEs · page 1 (more available)