CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Mar 11, 2025

Ashlar-Vellum Cobalt Buffer Overflow Vulnerability Leading to Remote Code Execution

A buffer overflow vulnerability has been identified in Ashlar-Vellum Cobalt within the CO file parsing component. This flaw allows remote attackers to execute arbitrary code on affected systems. The vulnerability arises from inadequate validation of user-supplied data lengths before copying them to a buffer, creating an opportunity for code execution in the context of the current process. Exploitation requires user interaction, such as opening a malicious file or visiting a harmful webpage.

1.6
Mar 11, 2025

Ashlar-Vellum Cobalt VC6 File Parsing Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability allowing remote code execution has been identified in Ashlar-Vellum Cobalt, specifically within the VC6 file parsing process. This issue arises from inadequate validation of user-supplied data, leading to a type confusion condition. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.

1.6
Mar 11, 2025

Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Ashlar-Vellum Cobalt, specifically within the parsing of VS files. This issue arises from improper validation of user-supplied data, leading to a type confusion condition. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage. Once exploited, the vulnerability allows attackers to execute arbitrary code in the context of the current process.

1.6
Mar 11, 2025

Ashlar-Vellum Cobalt Remote Code Execution Vulnerability Due to Uninitialized Variable in VS File Parsing

A remote code execution vulnerability has been identified in Ashlar-Vellum Cobalt, specifically within the parsing of VS files. The issue arises from the improper initialization of memory before it is accessed, allowing remote attackers to execute arbitrary code on affected installations. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.

1.6
Mar 11, 2025

Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability

A use-after-free vulnerability has been identified in Ashlar-Vellum Cobalt, specifically within the CO file parsing process. This flaw allows remote attackers to execute arbitrary code on affected systems. The vulnerability arises from improper validation of object existence before performing operations, creating an opportunity for exploitation. Notably, user interaction is required, as the target must open a malicious CO file.

1.6
Mar 11, 2025

Ashlar-Vellum Cobalt Out-of-Bounds Read Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Ashlar-Vellum Cobalt, specifically within the parsing of VS files. This issue arises from inadequate validation of user-supplied data, leading to a read past the end of an allocated buffer. Exploitation of this vulnerability requires user interaction, as the target must open a malicious file or visit a harmful webpage.

1.6
Mar 11, 2025

WordPress DP ALTerminator Missing ALT Manager Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress DP ALTerminator - Missing ALT manager plugin, affecting versions through 1.0.2. This issue arises from improper input neutralization during web page generation, which allows for the injection of malicious scripts that are executed when users visit the affected site.

1.5
Mar 11, 2025

WordPress Spam Byebye Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Spam Byebye plugin, specifically in versions through 2.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Mar 11, 2025

WordPress Back To Top Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Back To Top plugin, specifically in versions 2.0 and prior. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress WP Performance Pack Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress WP Performance Pack plugin, specifically in versions through 2.5.3. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions that require higher privileges.

1.8
Mar 11, 2025

Lava Code Lava Ajax Search Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Lava Ajax Search WordPress plugin, affecting versions through 1.1.9. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Mar 11, 2025

Sakurapixel Lunar WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Sakurapixel Lunar WordPress plugin, affecting versions through 1.3.0. This vulnerability arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Mar 11, 2025

WordPress MaxA/B Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress MaxA/B plugin, specifically in versions through 2.2.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress Insert Code Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Insert Code plugin, specifically in versions through 2.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the website.

2.0
Mar 11, 2025

DevriX WordPress Hashtags Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the DevriX WordPress Hashtags plugin, specifically in versions through 0.3.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress List Mixcloud Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress List Mixcloud plugin, affecting versions through 1.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.

1.6
Mar 11, 2025

Vivek Marakana Tabbed Login Widget Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Tabbed Login Widget plugin, affecting versions through 1.1.2. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.7
Mar 11, 2025

WordPress Display Template Name Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Display Template Name plugin, affecting versions through 1.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress Post Read Time Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Post Read Time plugin, specifically in versions through 1.2.6. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.5
Mar 11, 2025

Hieu Nguyen WATI Chat and Notification Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WATI Chat and Notification WordPress plugin, specifically in versions through 1.1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Mar 11, 2025

WordPress No Disposable Email Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress No Disposable Email plugin, affecting versions through 2.5.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress Go To Top Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Go To Top plugin, specifically in versions through 0.0.8. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Mar 11, 2025

WordPress Responsive Google Map Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the WordPress Responsive Google Map plugin, affecting versions through 3.1.5. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

2.6
Mar 11, 2025

WordPress Easy Image Display Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Easy Image Display plugin, affecting versions through 1.2.5. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

1.6
Mar 11, 2025

WordPress Featured Image Thumbnail Grid Plugin Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Featured Image Thumbnail Grid plugin, affecting versions through 6.8. The issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the site.

1.7
Mar 11, 2025

ThemeEgg Toolkit WordPress Plugin Arbitrary File Upload Vulnerability

A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the ThemeEgg Toolkit WordPress plugin, affecting versions through 1.2.9. This vulnerability could be exploited to upload a web shell to the server, potentially leading to unauthorized access or control over the website.

1.7
Mar 11, 2025

WordPress Login Form to Anywhere Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Login Form to Anywhere plugin, specifically in versions through 0.2. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when users visit the affected site.

1.5
Mar 11, 2025

WordPress WP Add Active Class To Menu Item Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress plugin 'WP Add Active Class To Menu Item' versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress Custom Dashboard Page Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Custom Dashboard Page plugin, specifically in versions through 1.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress WP Hide Admin Bar Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Hide Admin Bar plugin for WordPress, specifically in versions through 2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress WP No-Bot Question Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP No-Bot Question plugin, affecting versions through 0.1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

pipdig pipDisqus WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the pipdig pipDisqus WordPress plugin, affecting versions through 1.6. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when guests visit the site.

1.5
Mar 11, 2025

WordPress WP Last Modified Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress WP Last Modified plugin, affecting versions through 0.1. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject harmful scripts that are executed when users visit the affected site.

1.5
Mar 11, 2025

Thiago S.F. Skitter Slideshow Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Thiago S.F. Skitter Slideshow WordPress plugin, affecting versions through 2.5.2. This vulnerability arises from improper input sanitization during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.

1.5
Mar 11, 2025

Chaser324 Featured Posts Grid Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Chaser324 Featured Posts Grid plugin for WordPress, affecting versions through 1.7. This vulnerability arises from improper input sanitization during web page generation, allowing malicious users to inject harmful scripts that are executed when the affected page is viewed.

2.0
Mar 11, 2025

WordPress Contact Form 7 Select Box Editor Button CSRF Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Contact Form 7 Select Box Editor Button plugin, affecting versions through 0.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress Members Page Only for Logged-in Users Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Members Page Only for Logged-in Users plugin, affecting versions through 1.4.2. This vulnerability allows for Stored Cross-Site Scripting, as it enables attackers to trick users with higher privileges into performing actions that could introduce malicious scripts, which are then permanently stored and potentially executed later.

2.0
Mar 11, 2025

WordPress TabGarb Pro Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress TabGarb Pro plugin, affecting versions through 2.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Mar 11, 2025

Steveorevo Domain Theme Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Steveorevo Domain Theme, specifically in versions through 1.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the theme's insufficient protection against CSRF, enabling attackers to manipulate users with higher privileges into performing actions that could introduce malicious scripts, which are then permanently stored and executed.

2.0
Mar 11, 2025

Akshar Soft Solutions AS English Admin Open Redirect Vulnerability

A URL redirection vulnerability allowing untrusted site redirection (open redirect) has been identified in the Akshar Soft Solutions AS English Admin plugin, affecting versions through 1.0.0. This vulnerability could be exploited for phishing attacks by redirecting users to malicious sites.

2.5
Mar 11, 2025

WordPress Custom Top Bar Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Custom Top Bar plugin, specifically in versions through 2.0.2. This issue arises from improper input neutralization during web page generation, allowing malicious users to inject harmful scripts that are executed when the page is viewed.

2.0
Mar 11, 2025

WordPress List of Posts from Each Category Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the 'List of Posts from each Category' plugin for WordPress, affecting versions through 2.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress FTP Sync Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress FTP Sync plugin, specifically in versions through 1.1.6. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Mar 11, 2025

WordPress Price-Calc Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Price-Calc plugin, specifically in versions through 0.6.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Mar 11, 2025

WordPress Fastmover Plugins Last Updated Column Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Fastmover WordPress plugin 'Last Updated Column', affecting versions through 0.1.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress REST API TO MiniProgram Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress REST API TO MiniProgram plugin, affecting versions through 4.7.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

WordPress WP Bulk Post Duplicator Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WP Bulk Post Duplicator plugin, affecting versions through 1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Mar 11, 2025

WordPress WP Compare Tables Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Compare Tables plugin, specifically in versions through 1.0.5. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the application.

2.0
Mar 11, 2025

WordPress Mobile Themes Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Mobile Themes plugin, specifically in versions through 1.1.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Mar 11, 2025

Bee Layer Slider Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Bee Layer Slider WordPress plugin, affecting versions through 1.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.

2.0