CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2025-46240 MEDIUM

WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerability

CVSS 6.5 EPSS 0.22% Apr 22, 2025
CVE-2025-46239 MEDIUM

WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerability

CVSS 6.5 EPSS 0.22% Apr 22, 2025
CVE-2024-5002 MEDIUM

User Submitted Posts < 20240516 - Admin+ Stored XSS

CVSS 4.8 EPSS 0.42% Jul 13, 2024
CVE-2024-0979 MEDIUM

Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scripting

CVSS 6.1 EPSS 0.37% Jun 13, 2024
CVE-2024-2470 MEDIUM

Simple Ajax Chat < 20240412 - Admin+ Stored XSS

CVSS 5.4 EPSS 0.33% Jun 4, 2024
CVE-2024-1983 HIGH

Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS

CVSS 7.1 EPSS 0.45% Mar 20, 2024
CVE-2023-45603 CRITICAL

WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Upload

CVSS 9.8 EPSS 0.90% Dec 20, 2023
CVE-2023-49743 MEDIUM

WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)

CVSS 5.9 EPSS 0.39% Dec 14, 2023
CVE-2023-5614 MEDIUM

Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVSS 6.4 EPSS 0.44% Oct 20, 2023
CVE-2023-4838 MEDIUM

The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.6…

CVSS 6.4 EPSS 0.36% Sep 9, 2023
CVE-2023-4779 MEDIUM

User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVSS 6.4 EPSS 0.38% Sep 6, 2023
CVE-2023-4308 HIGH

User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'

CVSS 7.2 EPSS 0.42% Aug 15, 2023
CVE-2019-25138 CRITICAL

User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Upload

CVSS 9.8 EPSS 2.33% Jun 7, 2023
CVE-2023-26517 MEDIUM

WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)

CVSS 5.9 EPSS 0.37% May 6, 2023
CVE-2022-27850 MEDIUM

WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability

CVSS 5.4 EPSS 0.40% Apr 15, 2022
CVE-2022-27849 HIGH

WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability

CVSS 7.5 EPSS 4.62% Apr 15, 2022
CVE-2022-1165 CRITICAL

Blackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofing

CVSS 9.1 EPSS 1.67% Apr 4, 2022
CVE-2022-25610 MEDIUM

WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability

CVSS 6.1 EPSS 0.72% Mar 25, 2022
CVE-2022-25601 MEDIUM

WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability

CVSS 6.1 EPSS 1.02% Mar 11, 2022
CVE-2021-24409 MEDIUM

Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)

CVSS 6.1 EPSS 1.72% Jul 12, 2021
CVE-2021-24408 MEDIUM

Prismatic < 2.8 - Contributor+ Stored XSS

CVSS 5.4 EPSS 0.62% Jul 12, 2021
CVE-2016-11001 MEDIUM

The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.

CVSS 6.1 EPSS 1.18% Sep 20, 2019

Showing 1 to 22 CVEs · page 1