Ulisting
by WordPress
Source repositories
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36876 | Med | 0.35 | 5.4 | 0.00 | Sep 27, 2021 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages. | ||
| CVE-2024-47344 | Med | 0.34 | 5.3 | 0.00 | Oct 7, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Stylemix uListing ulisting.This issue affects uListing: from n/a through <= 2.1.5. | ||
| CVE-2026-28078 | Med | 0.32 | 4.9 | 0.00 | Mar 5, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisting allows Path Traversal.This issue affects uListing: from n/a through <= 2.2.0. | ||
| CVE-2021-36877 | Med | 0.28 | 4.3 | 0.00 | Sep 27, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles. | ||
| CVE-2021-36878 | Med | 0.28 | 4.3 | 0.00 | Sep 27, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings. | ||
| CVE-2026-27392 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Contributor Broken Access Control in uListing <= 2.2.0 versions. | ||
| CVE-2026-27391 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in uListing <= 2.2.0 versions. |
- risk 0.35cvss 5.4epss 0.00
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.
- risk 0.34cvss 5.3epss 0.00
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Stylemix uListing ulisting.This issue affects uListing: from n/a through <= 2.1.5.
- risk 0.32cvss 4.9epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisting allows Path Traversal.This issue affects uListing: from n/a through <= 2.2.0.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in uListing <= 2.2.0 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
Page 2 of 2