Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities Ldap Injection Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity WordPress Plugin Newsletter Manager Multiple Cross-Site Scripting Vulnerabilities (1.0.1) CVE-2012-6627 CVE-2012-6628 CWE-79 CWE-79 High WordPress Plugin Newsletter Manager PHP Object Injection (1.5.1) CWE-915 CWE-915 High WordPress Plugin Newsletter Meenews 'idnews' Parameter Cross-Site Scripting (5.1.0) CWE-79 CWE-79 High WordPress Plugin Newsletters Cross-Site Scripting (4.6.18) CWE-79 CWE-79 High WordPress Plugin Newsletters Multiple Vulnerabilities (4.6.5.3) CWE-79 CWE-538 CWE-79 CWE-538 High WordPress Plugin Newsletters Multiple Vulnerabilities (4.6.6.2) CWE-352 CWE-434 CWE-352 CWE-434 High WordPress Plugin Newsletters Multiple Vulnerabilities (4.6.14) CVE-2019-14787 CVE-2019-14788 CWE-79 CWE-94 CWE-79 CWE-94 High WordPress Plugin Newsletters PHP Object Injection (4.6.8.5) CWE-915 CWE-915 High WordPress Plugin Newsletter Subscription Form Possible Remote Code Execution (1.1.2) CVE-2016-10033 CVE-2016-10045 CWE-94 CWE-94 High WordPress Plugin Newsletters Unspecified Vulnerability (4.5.5.2) High WordPress Plugin Newspack Blocks Arbitrary File Upload (3.0.8) CVE-2024-37424 CWE-434 CWE-434 High WordPress Plugin NewsPlugin Cross-Site Request Forgery (1.0.18) CVE-2021-34631 CWE-352 CWE-352 High WordPress Plugin NewStatPress Cross-Site Scripting (1.0.3) CWE-79 CWE-79 High WordPress Plugin NewStatPress Cross-Site Scripting (1.0.5) CWE-79 CWE-79 High WordPress Plugin NewStatPress Cross-Site Scripting (1.2.4) CWE-79 CWE-79 High WordPress Plugin NewStatPress Multiple Vulnerabilities (0.9.8) CVE-2015-4062 CVE-2015-4063 CWE-79 CWE-89 CWE-79 CWE-89 High WordPress Plugin NewStatPress Multiple Vulnerabilities (1.0.4) CVE-2015-9312 CVE-2015-9313 CWE-79 CWE-89 CWE-79 CWE-89 High WordPress Plugin New Year Firework Cross-Site Scripting (1.1.9) CVE-2016-1000140 CWE-79 CWE-79 High WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder Security Bypass (7.8.7) CVE-2021-34675 CVE-2021-34676 CWE-264 CWE-264 High WordPress Plugin NEX-Forms-Ultimate Form builder Multiple SQL Injection Vulnerabilities (4.0) CWE-89 CWE-89 High WordPress Plugin NEX-Forms-Ultimate Form builder SQL Injection (3.0) CWE-89 CWE-89 High WordPress Plugin NEX-Forms Lite-WordPress Contact Form builder Cross-Site Scripting (2.1.0) CVE-2014-7151 CWE-79 CWE-79 High WordPress Plugin NextCellent Gallery-NextGEN Legacy Cross-Site Scripting (1.9.17) CVE-2014-3123 CWE-79 CWE-79 High WordPress Plugin NextCellent Gallery-NextGEN Legacy Cross-Site Scripting (1.9.27) CWE-79 CWE-79 High WordPress Plugin Nextend Facebook Connect Cross-Site Scripting (1.5.0) CVE-2014-8800 CWE-79 CWE-79 High WordPress Plugin Nextend Facebook Connect Cross-Site Scripting (1.5.5) CVE-2015-4413 CWE-79 CWE-79 High WordPress Plugin Nextend Facebook Connect Unspecified Vulnerability (1.5.7) High WordPress Plugin Nextend Google Connect Cross-Site Scripting (1.5.0) CWE-79 CWE-79 High WordPress Plugin Nextend Google Connect Cross-Site Scripting (1.5.2) CVE-2015-4557 CWE-79 CWE-79 High WordPress Plugin Nextend Google Connect Unspecified Vulnerability (1.5.3) High WordPress Plugin Nextend Twitter Connect Cross-Site Scripting (1.5.0) CWE-79 CWE-79 High WordPress Plugin Nextend Twitter Connect Cross-Site Scripting (1.5.1) CVE-2015-4557 CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery 'Gallery Path' Field Cross-Site Scripting (1.9.5) CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery 'nggallery-manage-gallery' HTML Injection (0.96) CVE-2008-7175 CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery 'swfupload.swf' Cross-Site Scripting (1.9.7) CVE-2012-3414 CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery 'xml/media-rss.php' Cross-Site Scripting (1.5.1) CVE-2010-1186 CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery Arbitrary File Upload (1.9.12) CVE-2013-3684 CWE-434 CWE-434 High WordPress Plugin NextGEN Gallery-WordPress Gallery Arbitrary File Upload (2.1.10) CWE-434 CWE-434 High WordPress Plugin NextGEN Gallery-WordPress Gallery Cross-Site Scripting (2.2.10) CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery Cross-Site Scripting and Cross-Site Request Forgery Vulnerabilities (1.8.3) CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery Directory Traversal (2.0.0) CWE-22 CWE-22 High WordPress Plugin NextGEN Gallery-WordPress Gallery Directory Traversal (2.1.9) CWE-22 CWE-22 High WordPress Plugin NextGEN Gallery-WordPress Gallery Information Disclosure (1.9.11) CVE-2013-0291 CWE-200 CWE-200 High WordPress Plugin NextGEN Gallery-WordPress Gallery Local File Inclusion (2.1.7) CWE-22 CWE-22 High WordPress Plugin NextGEN Gallery-WordPress Gallery Local File Inclusion (2.1.56) CVE-2016-6565 CWE-22 CWE-22 High WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple Cross-Site Request Forgery Vulnerabilities (3.4.7) CVE-2020-35942 CVE-2020-35943 CWE-352 CWE-352 High WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple Cross-Site Scripting Vulnerabilities (2.0.66.16) CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple Cross-Site Scripting Vulnerabilities (2.1.9) CVE-2015-9537 CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple Cross-Site Scripting Vulnerabilities (2.1.20) CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple HTML Injection Vulnerabilities (1.9.0) CWE-79 CWE-79 High WordPress Plugin NextGEN Gallery-WordPress Gallery Multiple Vulnerabilities (2.0.77) CVE-2015-1784 CVE-2015-1785 CWE-352 CWE-434 CWE-352 CWE-434 High WordPress Plugin NextGEN Gallery-WordPress Gallery PHP Object Injection (3.1.5) CWE-915 CWE-915 High WordPress Plugin NextGEN Gallery-WordPress Gallery Privilege Escalation (3.2.2) CWE-264 CWE-264 High WordPress Plugin NextGEN Gallery-WordPress Gallery Remote Code Execution (2.1.59) CWE-94 CWE-94 High WordPress Plugin NextGEN Gallery-WordPress Gallery Security Bypass (3.1.6) CWE-264 CWE-264 High WordPress Plugin NextGEN Gallery-WordPress Gallery SQL Injection (2.1.77) CWE-89 CWE-89 High WordPress Plugin NextGEN Gallery-WordPress Gallery SQL Injection (3.2.10) CVE-2019-14314 CWE-89 CWE-89 High WordPress Plugin NextGEN Gallery-WordPress Gallery Unspecified Vulnerability (2.0.77.3) High WordPress Plugin NextGEN Gallery-WordPress Gallery Unspecified Vulnerability (2.2.46) CVE-2018-7586 High WordPress Plugin NextGEN Gallery Sell Photo Cross-Site Scripting (1.0.4) CWE-79 CWE-79 High WordPress Plugin NextGEN Pro Cross-Site Scripting (3.1.9) CVE-2021-24293 CWE-79 CWE-79 High WordPress Plugin NextGEN Smooth Gallery 'galleryID' Parameter SQL Injection (1.2) CWE-89 CWE-89 High WordPress Plugin NextMove Lite-Thank You Page for WooCommerce Cross-Site Request Forgery (2.18.1) CVE-2024-32104 CWE-352 CWE-352 High WordPress Plugin NextMove Lite-Thank You Page for WooCommerce Security Bypass (2.17.0) CVE-2024-25092 CWE-862 CWE-862 High WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Request Forgery (4.3.24) CVE-2021-25072 CWE-352 CWE-352 High WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (3.4.17) CWE-79 CWE-79 High WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.2.7) CVE-2019-9911 CWE-79 CWE-79 High WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.3.20) CVE-2021-38356 CWE-79 CWE-79 High WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.3.23) CVE-2021-24975 CWE-79 CWE-79 High WordPress Plugin NextScripts:Social Networks Auto-Poster Security Bypass (4.3.17) CWE-264 CWE-264 High WordPress Plugin NextScripts:Social Networks Auto-Poster Unspecified Vulnerability (4.3.2) High WordPress Plugin Nginx Helper Cross-Site Scripting (1.8.9) CWE-79 CWE-79 High WordPress Plugin Nifty Newsletters (Formerly Sola Newsletters) Cross-Site Request Forgery (4.0.23) CVE-2021-34634 CWE-352 CWE-352 High WordPress Plugin Ninja Announcements Lite 'ninja_annc.php' SQL Injection (1.2.3) CWE-89 CWE-89 High WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder Cross-Site Request Forgery (3.4.24.1) CVE-2020-12462 CWE-352 CWE-352 High 1...113114115116...169 114 / 169