CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
WP-Optimize < 4.2.0 - Admin+ SQLi
All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting
UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update
WordPress Updraft Plugin <= 0.6.1 is vulnerable to Cross Site Scripting (XSS)
Multiple Plugins - Cross-Site Scripting From Third-party Library
WordPress UpdraftPlus Plugin <= 1.23.3 is vulnerable to Cross Site Request Forgery (CSRF)
All-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSS
All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversal
All In One WP Security & Firewall < 5.1.3 - Configuration Leak
All In One WP Security & Firewall < 5.0.8 - IP Spoofing
UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting
UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download
UpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting
UpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scripting
UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/a…
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget…
Showing 1 to 19 CVEs · page 1