2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24479MEDIUM4.8The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them bac...
CVE-2021-24478MEDIUM5.4The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outpu...
CVE-2021-24477MEDIUM6.1The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a...
CVE-2021-24476MEDIUM5.4The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings befor...
CVE-2021-24474MEDIUM6.1The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refr...
CVE-2021-24473MEDIUM5.4The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_ima...
CVE-2021-24472CRITICAL9.8The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functional...
CVE-2021-24470MEDIUM5.4The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, ...
CVE-2021-24468MEDIUM5.4The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScri...
CVE-2021-24464MEDIUM5.4The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise som...
CVE-2021-24463HIGH8.8The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did ...
CVE-2021-24462HIGH8.8The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPr...
CVE-2021-24461HIGH8.8The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the order...
CVE-2021-24460HIGH8.8The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist ...
CVE-2021-24459HIGH8.8The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or v...
CVE-2021-24458HIGH8.8The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use...
CVE-2021-24457HIGH8.8The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php a...
CVE-2021-24456HIGH7.2The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters bef...
CVE-2021-24455MEDIUM5.4The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of A...
CVE-2021-24450MEDIUM4.8The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin befor...
CVE-2021-24448MEDIUM4.8The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Mo...
CVE-2021-24444MEDIUM4.8The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Tax...
CVE-2021-24443MEDIUM5.4The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin be...
CVE-2021-24430HIGH7.2The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude...
CVE-2021-24428MEDIUM4.8The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving an...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now