2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-39420MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities exist in VFront 0.99.5 via the (1) s parameter in search_all.php and...
CVE-2021-40577MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an...
CVE-2021-24840MEDIUM5.3The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve t...
CVE-2021-24832MEDIUM4.3The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could a...
CVE-2021-24816MEDIUM4.3The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX ...
CVE-2021-24807MEDIUM5.4The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting atta...
CVE-2021-24806MEDIUM4.3The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could a...
CVE-2021-24801MEDIUM4.3The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX act...
CVE-2021-24798MEDIUM6.1The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it bac...
CVE-2021-24788MEDIUM6.5The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are avai...
CVE-2021-24783MEDIUM6.5The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow user...
CVE-2021-24767MEDIUM6.5The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF w...
CVE-2021-24766MEDIUM6.5The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place whe...
CVE-2021-24721MEDIUM6.5The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed ...
CVE-2021-24710MEDIUM4.8The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute...
CVE-2021-24708MEDIUM4.8The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputti...
CVE-2021-24706MEDIUM4.8The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of...
CVE-2021-24701MEDIUM4.8The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managin...
CVE-2021-24698MEDIUM4.3The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumb...
CVE-2021-24697MEDIUM6.1The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm...
CVE-2021-24674MEDIUM6.5The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could a...
CVE-2021-24664MEDIUM4.8The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_fie...
CVE-2021-24646MEDIUM4.8The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, wh...
CVE-2021-24645MEDIUM4.8The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Pro...
CVE-2021-24616MEDIUM4.8The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now