Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Arbitrary File Creation Authentication Bypass Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities Ldap Injection Malware Missing Update Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity WordPress Plugin Zotpress 'citation' Parameter Cross-Site Scripting (2.6.1) CWE-79 CWE-79 High WordPress Plugin Zotpress 'zotpress.rss.php' SQL Injection (4.4) CWE-89 CWE-89 High WordPress Plugin Zotpress SQL Injection (6.1.2) CVE-2016-1000217 CWE-89 CWE-89 High WordPress Plugin ZTR Zeumic Work Timer Multiple Unspecified Vulnerabilities (1.0.6) High WordPress Plugin ZWM Zeumic Work Management Multiple Unspecified Vulnerabilities (1.0.11) High WordPress Plugin ZX_CSV Upload Multiple Vulnerabilities (1) CWE-89 CWE-352 CWE-89 CWE-352 High WordPress Possible Security Bypass Vulnerability (0.70 - 4.7.4) CVE-2017-8295 CWE-264 CWE-264 High WordPress Possible SQL Injection Vulnerability (0.70 - 3.6.1) CVE-2017-16510 CWE-89 CWE-89 High WordPress Same Origin Method Execution (SOME) Vulnerability (0.70 - 3.7.13) CVE-2016-4566 CWE-79 CWE-79 High WordPress Server-Side Request Forgery (3.7 - 6.1.1) CVE-2022-3590 CWE-918 CWE-918 High WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2016-4029) CVE-2016-4029 CWE-918 CWE-918 High WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-9066) CVE-2017-9066 CWE-918 CWE-918 High WordPress Super Socialat backdoor plugin CWE-94 CWE-94 High WordPress Theme OneTone: Unauthenticated Stored Cross-Site Scripting (XSS) CVE-2019-17230 CVE-2019-17231 CWE-79 CWE-79 High WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10673) CVE-2019-10673 CWE-352 CWE-352 High WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-31216) CVE-2023-31216 CWE-352 CWE-352 High WordPress Ultimate Member Plugin Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-3966) CVE-2022-3966 CWE-22 CWE-22 High WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36156) CVE-2020-36156 CWE-269 CWE-269 High WordPress Ultimate Member Plugin Other Vulnerability (CVE-2022-3383) CVE-2022-3383 High WordPress Ultimate Member Plugin Other Vulnerability (CVE-2022-3384) CVE-2022-3384 High WordPress Ultimate Member Plugin Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-10270) CVE-2019-10270 CWE-640 CWE-640 High WordPress Uncontrolled Resource Consumption Vulnerability (CVE-2018-6389) CVE-2018-6389 CWE-400 CWE-400 High WordPress Uncontrolled Resource Consumption Vulnerability (CVE-2023-22622) CVE-2023-22622 CWE-400 CWE-400 High WordPress Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-14028) CVE-2018-14028 CWE-434 CWE-434 High WordPress Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Vulnerability (CVE-2017-5493) CVE-2017-5493 CWE-338 CWE-338 High WordPress Use of Insufficiently Random Values Vulnerability (CVE-2017-17091) CVE-2017-17091 CWE-330 CWE-330 High WordPress User-Agent SQL Injection Vulnerability (1.5.2) CVE-2006-1012 CWE-89 CWE-89 High WordPress W3 Total Cache plugin predictable cache filenames CVE-2012-6077 CVE-2012-6078 CVE-2012-6079 CWE-200 CWE-200 High WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2014-6412) CVE-2014-6412 CWE-640 CWE-640 High WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2020-11027) CVE-2020-11027 CWE-640 CWE-640 High WPEngine _wpeprivate/config.json information disclosure CWE-200 CWE-200 High X-Forwarded-For HTTP header security bypass CWE-287 CWE-287 High Xdebug remote code execution via xdebug.remote_connect_back CWE-200 CWE-200 High XML quadratic blowup denial of service attack CWE-400 CWE-400 High XOOPS CVE-2009-3963 Vulnerability (CVE-2009-3963) CVE-2009-3963 High XOOPS Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-0612) CVE-2008-0612 CWE-22 CWE-22 High XOOPS Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-3296) CVE-2008-3296 CWE-22 CWE-22 High XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2002-2391) CVE-2002-2391 CWE-138 CWE-138 High XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-0611) CVE-2008-0611 CWE-138 CWE-138 High XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-4433) CVE-2008-4433 CWE-138 CWE-138 High XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-5665) CVE-2008-5665 CWE-138 CWE-138 High XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-7290) CVE-2017-7290 CWE-138 CWE-138 High XOOPS Other Vulnerability (CVE-2005-0743) CVE-2005-0743 High XOOPS Other Vulnerability (CVE-2005-2113) CVE-2005-2113 High XOOPS Other Vulnerability (CVE-2007-0377) CVE-2007-0377 High XPath injection vulnerability CWE-643 CWE-643 High XSLT injection CWE-91 CWE-91 High XWiki Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-50719) CVE-2023-50719 CWE-312 CWE-312 High XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-41927) CVE-2022-41927 CWE-352 CWE-352 High XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-29213) CVE-2023-29213 CWE-352 CWE-352 High XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-40572) CVE-2023-40572 CWE-352 CWE-352 High XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-46242) CVE-2023-46242 CWE-352 CWE-352 High XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-48293) CVE-2023-48293 CWE-352 CWE-352 High XWiki CVE-2022-31166 Vulnerability (CVE-2022-31166) CVE-2022-31166 High XWiki CVE-2023-26471 Vulnerability (CVE-2023-26471) CVE-2023-26471 High XWiki CVE-2023-26474 Vulnerability (CVE-2023-26474) CVE-2023-26474 High XWiki CVE-2023-35166 Vulnerability (CVE-2023-35166) CVE-2023-35166 High XWiki CVE-2023-40573 Vulnerability (CVE-2023-40573) CVE-2023-40573 High XWiki CVE-2023-48241 Vulnerability (CVE-2023-48241) CVE-2023-48241 High XWiki Exposure of Private Personal Information to an Unauthorized Actor Vulnerability (CVE-2022-41936) CVE-2022-41936 CWE-359 CWE-359 High XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-29208) CVE-2023-29208 CWE-668 CWE-668 High XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-34467) CVE-2023-34467 CWE-668 CWE-668 High XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-35151) CVE-2023-35151 CWE-668 CWE-668 High XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-29517) CVE-2023-29517 CWE-200 CWE-200 High XWiki Improper Authentication Vulnerability (CVE-2022-36092) CVE-2022-36092 CWE-287 CWE-287 High XWiki Improper Authentication Vulnerability (CVE-2022-36093) CVE-2022-36093 CWE-287 CWE-287 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-11057) CVE-2020-11057 CWE-94 CWE-94 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29209) CVE-2023-29209 CWE-94 CWE-94 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29210) CVE-2023-29210 CWE-94 CWE-94 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29211) CVE-2023-29211 CWE-94 CWE-94 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29212) CVE-2023-29212 CWE-94 CWE-94 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29214) CVE-2023-29214 CWE-94 CWE-94 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29509) CVE-2023-29509 CWE-94 CWE-94 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30537) CVE-2023-30537 CWE-94 CWE-94 High XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-35150) CVE-2023-35150 CWE-94 CWE-94 High 1...162163164165 163 / 165