BoldGrid / W3 Total Cache
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-87920 | W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content | HIGH | 7.2 | Oct 2, 2026 |
| CVE-2026-78438 | W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator | HIGH | 7.2 | Sep 5, 2026 |
| CVE-2026-18109 | W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name | HIGH | 7.2 | Aug 14, 2026 |
| CVE-2026-66695 | WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability | MEDIUM | 6.5 | Aug 6, 2026 |
| CVE-2026-9282 | W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter | HIGH | 7.5 | Jul 11, 2026 |
| CVE-2026-57623 | WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability | CRITICAL | 9.0 | Jul 2, 2026 |
| CVE-2026-39595 | WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability | MEDIUM | 4.7 | Jun 17, 2026 |
| CVE-2026-5032 | W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header | HIGH | 7.5 | Apr 2, 2026 |
| CVE-2026-27384 | WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability | CRITICAL | 9.0 | Mar 5, 2026 |
| CVE-2024-12008 | W3 Total Cache <= 2.8.1 Information Exposure via Log Files | HIGH | 7.5 | Jan 14, 2025 |
| CVE-2024-12006 | W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation | MEDIUM | 5.3 | Jan 14, 2025 |
| CVE-2024-12365 | W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery | HIGH | 8.5 | Jan 14, 2025 |
| CVE-2023-5359 | W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext | HIGH | 7.5 | Sep 24, 2024 |
| CVE-2021-24452 | W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context) | MEDIUM | 6.1 | Jul 19, 2021 |
| CVE-2021-24436 | W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context) | MEDIUM | 6.1 | Jul 19, 2021 |
| CVE-2021-24427 | W3 Total Cache < 2.1.3 - Authenticated Stored XSS | MEDIUM | 4.8 | Jul 12, 2021 |
| CVE-2013-2010 | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability | CRITICAL | 9.8 | Feb 12, 2020 |
| CVE-2012-6079 | W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys. | HIGH | 7.5 | Nov 22, 2019 |
| CVE-2012-6078 | W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes. | HIGH | 7.5 | Nov 22, 2019 |
| CVE-2012-6077 | W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files. | HIGH | 7.5 | Nov 22, 2019 |
| CVE-2019-6715 | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionC… | HIGH | 7.5 | Apr 1, 2019 |
| CVE-2014-9414 | The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forge… | MEDIUM | 6.8 | Dec 24, 2014 |
| CVE-2014-8724 | Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inje… | MEDIUM | 4.3 | Dec 19, 2014 |
Showing 1 to 16 of 16 CVEs