2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25112MEDIUM6.1The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back...
CVE-2021-25081MEDIUM6.5The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX action...
CVE-2021-25042MEDIUM5.4The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in...
CVE-2021-25034MEDIUM6.1The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortc...
CVE-2021-25011MEDIUM5.7The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most ...
CVE-2021-25010CRITICAL9.6The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make...
CVE-2021-24994MEDIUM6.1The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, a...
CVE-2021-24977MEDIUM6.1The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assign...
CVE-2021-24971MEDIUM5.4The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update A...
CVE-2021-24933MEDIUM5.4The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an...
CVE-2021-24920MEDIUM4.8The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, whic...
CVE-2021-24913MEDIUM4.3The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_...
CVE-2021-24903MEDIUM4.8The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which cou...
CVE-2021-24901MEDIUM4.8The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow hi...
CVE-2021-24898MEDIUM4.8The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which ...
CVE-2021-24864HIGH8.8The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a S...
CVE-2021-24823HIGH8.1The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php...
CVE-2021-24820MEDIUM6.5The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ ...
CVE-2021-24803HIGH8.8The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin...
CVE-2021-24730MEDIUM4.3The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lsw...
CVE-2021-24704HIGH8.8In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" per...
CVE-2021-24689MEDIUM4.9The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to downl...
CVE-2021-24688MEDIUM4.3The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls,...
CVE-2021-43945MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permission...
CVE-2021-21708CRITICAL9.8In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_V...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now