Updraftplus / Updraftplus
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-5982 | UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update | MEDIUM | 5.4 | Nov 7, 2023 |
| CVE-2023-32960 | WordPress UpdraftPlus Plugin <= 1.23.3 is vulnerable to Cross Site Request Forgery (CSRF) | HIGH | 7.1 | Jun 22, 2023 |
| CVE-2022-0864 | UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting | MEDIUM | 6.1 | Apr 4, 2022 |
| CVE-2022-0633 | UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download | MEDIUM | 6.5 | Feb 17, 2022 |
| CVE-2021-25089 | UpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting | MEDIUM | 6.1 | Feb 1, 2022 |
| CVE-2021-24423 | UpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scripting | MEDIUM | 4.8 | Jan 24, 2022 |
| CVE-2021-25022 | UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting | MEDIUM | 6.1 | Jan 3, 2022 |
| CVE-2015-9360 | The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg(). | MEDIUM | 6.1 | Aug 28, 2019 |
| CVE-2017-18593 | The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file. | MEDIUM | 6.1 | Aug 28, 2019 |
| CVE-2017-16871 | The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/a… | HIGH | 8.1 | Nov 17, 2017 |
| CVE-2017-16870 | The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget… | HIGH | 8.1 | Nov 17, 2017 |
Showing 1 to 11 of 11 CVEs