VYPR

Visualizer

by WordPress

Source repositories

CVEs (14)

  • CVE-2019-16932CriSep 30, 2019
    risk 0.68cvss 10.0epss 0.39

    A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

  • CVE-2024-35736HigJun 8, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visualizer: from n/a through 3.11.1.

  • CVE-2024-3750HigMay 16, 2024
    risk 0.50cvss 8.8epss 0.01

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on the getQueryData() function in all versions up to, and including, 3.10.15. This makes it possible…

  • CVE-2024-27958HigMar 17, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Reflected XSS.This issue affects Visualizer: from n/a through 3.10.5.

  • CVE-2026-19726MedAug 16, 2026
    risk 0.42cvss 6.5epss 0.00

    The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin…

  • CVE-2025-12483MedDec 2, 2025
    risk 0.42cvss 6.5epss 0.00

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'query' parameter in all versions up to, and including, 3.11.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

  • CVE-2019-16931MedOct 3, 2019
    risk 0.40cvss 6.1epss 0.03

    A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php…

  • CVE-2026-24573MedMay 20, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0.

  • CVE-2025-1065MedFeb 19, 2025
    risk 0.35cvss 6.4epss 0.00

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping on…

  • CVE-2026-8689MedMay 28, 2026
    risk 0.21cvss 4.3epss 0.00

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is due to a missing capability check on the renderChartPages() and uploadData() functions, where the…

  • CVE-2026-14939MedAug 4, 2026
    risk 0.00cvss 6.8epss 0.00

    The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata…

  • CVE-2026-15653MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-65526HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

  • CVE-2026-13468HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…