VYPR

CVEs

346,580 total · page 290 of 6,932

  • CVE-2022-50970MedMay 10, 2026
    risk 0.35cvss 5.4epss 0.00

    WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the tab parameter. Attackers can craft URLs with XSS payloads in the tab parameter of the aawp-settings admin page…

  • CVE-2022-50969MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the backend/mailingLog/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject…

  • CVE-2022-50968MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts…

  • CVE-2022-50967MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the tickets/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts…

  • CVE-2022-50966MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the news/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via…

  • CVE-2022-50965MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via…

  • CVE-2022-50964MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject…

  • CVE-2022-50963MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject…

  • CVE-2022-50962MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts…

  • CVE-2022-50961MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the…

  • CVE-2022-50960MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to…

  • CVE-2022-50959MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in…

  • CVE-2022-50958MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in…

  • CVE-2022-50957MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of…

  • CVE-2022-50956MedMay 10, 2026
    risk 0.40cvss 6.2epss 0.00

    WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter…

  • CVE-2022-50955MedMay 10, 2026
    risk 0.28cvss 4.3epss 0.00

    WordPress Plugin Curtain 1.0.2 contains a cross-site request forgery vulnerability that allows attackers to activate or deactivate site maintenance mode by crafting malicious requests. Attackers can trick authenticated administrators into submitting forged requests to the…

  • CVE-2022-50954MedMay 10, 2026
    risk 0.40cvss 6.2epss 0.00

    WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the controller parameter in tblight.php. Attackers can supply path traversal sequences through the controller…

  • CVE-2022-50949MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus…

  • CVE-2022-50948MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters…

  • CVE-2022-50947MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript…

  • CVE-2022-50946MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin Netroics Blog Posts Grid 1.0 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject script payloads through…

  • CVE-2022-50945MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or…

  • CVE-2022-50944HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.00

    Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image parameter. Attackers can upload PHP files with embedded code to the admin posts.php endpoint with…

  • CVE-2022-50943MedMay 10, 2026
    risk 0.40cvss 6.1epss 0.00

    Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary…

  • CVE-2021-47953MedMay 10, 2026
    risk 0.28cvss 4.3epss 0.00

    OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the…

  • CVE-2021-47951MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access Control settings. Attackers can enter JavaScript payloads in the plugin options…

  • CVE-2021-47950MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulating the s_emotion parameter. Attackers can submit POST requests to admin.php with…

  • CVE-2021-47949HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.01

    CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in…

  • CVE-2021-47948MedMay 10, 2026
    risk 0.35cvss 5.4epss 0.00

    WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers can inject malicious HTML including image tags and scripts into the Help Text…

  • CVE-2021-47947MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input in the 'name' parameter of files-edit.php. Attackers can inject JavaScript payloads through the file name field that…

  • CVE-2021-47946MedMay 10, 2026
    risk 0.34cvss 5.3epss 0.00

    OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiting malicious pages. Attackers can craft CSRF payloads that change victim email…

  • CVE-2021-47945HigMay 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be…

  • CVE-2021-47944HigMay 10, 2026
    risk 0.49cvss 7.5epss 0.00

    memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note…

  • CVE-2021-47943HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.01

    TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functionality. Attackers can upload a PHP shell via the Files section in the content…

  • CVE-2021-47941HigMay 10, 2026
    risk 0.53cvss 8.2epss 0.00

    WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract…

  • CVE-2021-47940CriMay 10, 2026
    risk 0.64cvss 9.8epss 0.00

    WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint…

  • CVE-2021-47939HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST requests to /manager/index.php with…

  • CVE-2021-47938HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.01

    ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code into the sat_code parameter. Attackers can authenticate, submit a POST request…

  • CVE-2021-47937HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.01

    e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that…

  • CVE-2021-47936CriMay 10, 2026
    risk 0.64cvss 9.8epss 0.01

    OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and…

  • CVE-2021-47935HigMay 10, 2026
    risk 0.50cvss 8.8epss 0.01

    Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin…

  • CVE-2021-47933CriMay 10, 2026
    risk 0.64cvss 9.8epss 0.01

    WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to…

  • CVE-2021-47932CriMay 10, 2026
    risk 0.64cvss 9.8epss 0.00

    WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action…

  • CVE-2021-47931MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to…

  • CVE-2021-47930HigMay 10, 2026
    risk 0.53cvss 8.2epss 0.00

    Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in…

  • CVE-2021-47929MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that…

  • CVE-2021-47928HigMay 10, 2026
    risk 0.53cvss 8.2epss 0.00

    Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id parameter. Attackers can craft malicious SQL queries using time-based or content-based…

  • CVE-2021-47927MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin…

  • CVE-2021-47926MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes…

  • CVE-2021-47925MedMay 10, 2026
    risk 0.42cvss 6.4epss 0.00

    CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters…