Vulnerabilities (CVE)

Total 398785 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1002024 1 Kindsoft 2 Kind Editor, Kindeditor 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.
CVE-2017-1002023 1 Daisythemes 1 Easy Team Manager 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin Easy Team Manager v1.3.2, The code does not sanitize id before making it part of an SQL statement in file ./easy-team-manager/inc/easy_team_manager_desc_edit.php
CVE-2017-1002022 1 Surveys Project 1 Surveys 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query.
CVE-2017-1002021 1 Surveys Project 1 Surveys 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.
CVE-2017-1002020 1 Surveys Project 1 Surveys 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.
CVE-2017-1002019 1 Eventr Project 1 Eventr 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this allows for blind SQL injection via the event parameter.
CVE-2017-1002018 1 Eventr Project 1 Eventr 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this allows for blind SQL injection via the event parameter.
CVE-2017-1002017 1 Bobcares 1 Gift-certificate-creator 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Vulnerability in wordpress plugin gift-certificate-creator v1.0, The code in gc-list.php doesn't sanitize user input to prevent a stored XSS vulnerability.
CVE-2017-1002016 1 Flickr Picture Backup Project 1 Flickr Picture Backup 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files.
CVE-2017-1002015 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.
CVE-2017-1002014 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
CVE-2017-1002013 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.
CVE-2017-1002012 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.
CVE-2017-1002011 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 3.5 LOW 5.4 MEDIUM
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.
CVE-2017-1002010 1 Ontraport 1 Membership Simplified 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function.
CVE-2017-1002009 1 Ontraport 1 Membership Simplified 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.
CVE-2017-1002008 1 Membership Simplified Project 1 Membership Simplified 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.
CVE-2017-1002007 1 Dtracker Project 1 Dtracker 2026-06-17 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
CVE-2017-1002006 1 Dtracker Project 1 Dtracker 2026-06-17 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
CVE-2017-1002005 1 Dtracker Project 1 Dtracker 2026-06-17 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.