CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
WordPress Automatic Featured Images from Videos plugin <= 1.2.7 - Broken Access Control vulnerability
Custom Post Type UI <= 1.18.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'label' Import Parameter
Custom Post Type UI <= 1.18.0 - Missing Authorization to Unauthenticated (Previously Administrator+) Custom Post Type Modification
WordPress Constant Contact for WordPress Plugin <= 4.1.1 - PHP Object Injection Vulnerability
WordPress Automatic Featured Images from Videos plugin <= 1.2.4 - Broken Access Control vulnerability
WDS Multisite Aggregate Plugin WDS_Multisite_Aggregate_Options.php update_options cross site scripting
Custom Post Type UI < 1.13.5 - Debug Info Sending via CSRF
WebDevStudios taxonomy-switcher Plugin taxonomy-switcher.php taxonomy_switcher_init cross site scripting
PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Showing 1 to 9 CVEs · page 1