CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2025-3951 MEDIUM

WP-Optimize < 4.2.0 - Admin+ SQLi

CVSS 4.1 EPSS 0.32% Jun 2, 2025
CVE-2024-1037 MEDIUM

All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting

CVSS 6.1 EPSS 0.55% Feb 7, 2024
CVE-2023-5982 MEDIUM

UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update

CVSS 5.4 EPSS 0.22% Nov 7, 2023
CVE-2023-26530 HIGH

WordPress Updraft Plugin <= 0.6.1 is vulnerable to Cross Site Scripting (XSS)

CVSS 7.1 EPSS 0.38% Aug 17, 2023
CVE-2023-1119 MEDIUM

Multiple Plugins - Cross-Site Scripting From Third-party Library

CVSS 6.1 EPSS 1.24% Jul 10, 2023
CVE-2023-32960 HIGH

WordPress UpdraftPlus Plugin <= 1.23.3 is vulnerable to Cross Site Request Forgery (CSRF)

CVSS 7.1 EPSS 0.21% Jun 22, 2023
CVE-2023-0157 MEDIUM

All-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSS

CVSS 4.8 EPSS 32.46% Apr 10, 2023
CVE-2023-0156 MEDIUM

All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversal

CVSS 4.9 EPSS 19.92% Apr 10, 2023
CVE-2022-4346 MEDIUM

All In One WP Security & Firewall < 5.1.3 - Configuration Leak

CVSS 5.3 EPSS 0.66% Jan 23, 2023
CVE-2022-4097 MEDIUM

All In One WP Security & Firewall < 5.0.8 - IP Spoofing

CVSS 5.3 EPSS 0.58% Dec 12, 2022
CVE-2022-0864 MEDIUM

UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting

CVSS 6.1 EPSS 7.41% Apr 4, 2022
CVE-2022-0633 MEDIUM

UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download

CVSS 6.5 EPSS 2.07% Feb 17, 2022
CVE-2021-25089 MEDIUM

UpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting

CVSS 6.1 EPSS 0.80% Feb 1, 2022
CVE-2021-24423 MEDIUM

UpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scripting

CVSS 4.8 EPSS 0.61% Jan 24, 2022
CVE-2021-25022 MEDIUM

UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting

CVSS 6.1 EPSS 1.12% Jan 3, 2022
CVE-2015-9360 MEDIUM

The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVSS 6.1 EPSS 0.95% Aug 28, 2019
CVE-2017-18593 MEDIUM

The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.

CVSS 6.1 EPSS 0.92% Aug 28, 2019
CVE-2017-16871 HIGH

The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/a…

CVSS 8.1 EPSS 1.65% Nov 17, 2017
CVE-2017-16870 HIGH

The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget…

CVSS 8.1 EPSS 0.96% Nov 17, 2017

Showing 1 to 19 CVEs · page 1