CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2024-8252 HIGH

Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion

CVSS 8.8 EPSS 3.03% Aug 30, 2024
CVE-2024-38787 HIGH

WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability

CVSS 7.5 EPSS 0.42% Aug 13, 2024
CVE-2024-34815 MEDIUM

WordPress Import and export users and customers plugin <= 1.26.5 - Broken Access Control vulnerability

CVSS 5.4 EPSS 0.37% Jun 11, 2024
CVE-2024-22151 MEDIUM

WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability

CVSS 5.3 EPSS 0.32% Jun 8, 2024
CVE-2024-4734 MEDIUM

Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

CVSS 4.4 EPSS 0.29% May 15, 2024
CVE-2023-6583 HIGH

Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality

CVSS 7.2 EPSS 0.80% Jan 11, 2024
CVE-2023-6624 MEDIUM

Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

CVSS 5.4 EPSS 0.35% Jan 11, 2024
CVE-2022-4838 MEDIUM

Clean Login < 1.13.7 - Contributor+ Stored XSS via Shortcode

CVSS 5.4 EPSS 0.57% Feb 6, 2023
CVE-2022-3558 HIGH

Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection

CVSS 8.0 EPSS 1.09% Nov 7, 2022
CVE-2022-1255 MEDIUM

Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting

CVSS 4.8 EPSS 0.71% May 2, 2022
CVE-2020-22277 HIGH

Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

CVSS 8.0 EPSS 1.85% Nov 4, 2020
CVE-2019-15326 HIGH

The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

CVSS 7.5 EPSS 2.32% Aug 22, 2019
CVE-2019-15327 MEDIUM

The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

CVSS 6.1 EPSS 0.91% Aug 22, 2019
CVE-2019-15328 MEDIUM

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

CVSS 6.1 EPSS 0.93% Aug 22, 2019
CVE-2019-15329 HIGH

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

CVSS 8.8 EPSS 0.69% Aug 22, 2019
CVE-2015-9336 MEDIUM

The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

CVSS 6.1 EPSS 0.92% Aug 22, 2019
CVE-2019-14683 MEDIUM

The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

CVSS 5.7 EPSS 0.68% Aug 8, 2019
CVE-2018-20101 MEDIUM

The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

CVSS 6.1 EPSS 0.78% Dec 12, 2018
CVE-2017-8875 MEDIUM

CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.

CVSS 6.5 EPSS 0.62% May 10, 2017

Showing 1 to 19 CVEs · page 1