2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24896MEDIUM4.8The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attri...
CVE-2021-24872MEDIUM6.5The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other p...
CVE-2021-24871MEDIUM5.4The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the pa...
CVE-2021-24859MEDIUM4.3The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as c...
CVE-2021-24855MEDIUM5.4The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their conte...
CVE-2021-24845MEDIUM6.5The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status ...
CVE-2021-24836MEDIUM4.3The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when upda...
CVE-2021-24819MEDIUM4.3The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users...
CVE-2021-24818MEDIUM4.3The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make ...
CVE-2021-24817MEDIUM5.4The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, ...
CVE-2021-24795MEDIUM6.5The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleti...
CVE-2021-24792MEDIUM6.1The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a templat...
CVE-2021-24790MEDIUM4.3The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks...
CVE-2021-24784MEDIUM6.5The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could al...
CVE-2021-24782MEDIUM4.8The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could...
CVE-2021-24780MEDIUM4.3The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could ...
CVE-2021-24771MEDIUM4.8The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields whe...
CVE-2021-24756MEDIUM6.1The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from lo...
CVE-2021-24705MEDIUM4.8The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape ...
CVE-2021-20867MEDIUM6.5Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au...
CVE-2021-20866MEDIUM6.5Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au...
CVE-2021-44155MEDIUM5.3An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response i...
CVE-2021-40858MEDIUM4.9Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin pa...
CVE-2021-44848MEDIUM5.3In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques...
CVE-2021-4097MEDIUM5.4phpservermon is vulnerable to Improper Neutralization of CRLF Sequences

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now