Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Sensitive Information Disclosure Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Xss - Known Vulnerabilities Vulnerability Name CVE CWE CWE Severity WordPress Plugin NotificationX-WooCommerce Sales Notification Popup, Custom & Live Sales Notification, FOMO, Social Proof, Announcement Banner & Sticky Notification Bar SQL Injection (2.8.2) CVE-2024-1698 CWE-89 CWE-89 High WordPress Plugin NS Utilities Unspecified Vulnerability (1.0) High WordPress Plugin Numbers generator and validator Multiple Unspecified Vulnerabilities (1.02) High WordPress Plugin O2Tweet Cross-Site Request Forgery (0.0.4) CVE-2014-9338 CWE-352 CWE-352 High WordPress Plugin OAuth client Single Sign On for WordPress (OAuth 2.0 SSO) Security Bypass (3.0.3) CVE-2022-3119 CWE-287 CWE-287 High WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Cross-Site Scripting (6.20.2) CWE-79 CWE-79 High WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Multiple Cross-Site Request Forgery Vulnerabilities (6.24.1) CVE-2023-1092 CVE-2023-1093 CWE-352 CWE-352 High WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Security Bypass (6.22.5) CVE-2022-2133 CWE-287 CWE-287 High WordPress Plugin Occasions Cross-Site Request Forgery (1.0.4) CWE-352 CWE-352 High WordPress Plugin Ocean Extra Cross-Site Request Forgery (1.6.5) CWE-352 CWE-352 High WordPress Plugin Ocean Extra Cross-Site Scripting (1.9.4) CVE-2021-25104 CWE-79 CWE-79 High WordPress Plugin Ocean Extra Cross-Site Scripting (2.1.1) CVE-2023-23891 CWE-79 CWE-79 High WordPress Plugin Ocean Extra Multiple Vulnerabilities (2.1.2) CVE-2023-0749 CVE-2023-24399 CWE-79 CWE-639 CWE-79 CWE-639 High WordPress Plugin Ocean Extra PHP Object Injection (2.0.4) CVE-2022-3374 CWE-915 CWE-915 High WordPress Plugin Ocean Extra Security Bypass (1.5.8) CVE-2019-16250 CWE-264 CWE-264 High WordPress Plugin OdiHost Newsletter 'openstat.php' SQL Injection (1.0) CWE-89 CWE-89 High WordPress Plugin Official MailerLite Sign Up Forms Cross-Site Request Forgery (1.4.4) CWE-352 CWE-352 High WordPress Plugin Official MailerLite Sign Up Forms SQL Injection (1.4.3) CWE-89 CWE-89 High WordPress Plugin OG Tags Cross-Site Request Forgery (2.0.1) CVE-2021-20831 CWE-352 CWE-352 High WordPress Plugin Oi Yandex.Maps for WordPress Cross-Site Scripting (3.2.7) CVE-2023-22721 CWE-79 CWE-79 High WordPress Plugin Oleggo LiveStream Cross-Site Scripting (0.2.6) CVE-2014-4540 CWE-79 CWE-79 High WordPress Plugin Olevmedia Shortcodes Cross-Site Scripting (1.1.8) CWE-79 CWE-79 High WordPress Plugin Olevmedia Shortcodes Multiple Cross-Site Scripting Vulnerabilities (1.1.9) CVE-2023-0168 CVE-2023-25798 CWE-79 CWE-79 High WordPress Plugin Olimometer SQL Injection (2.56) CWE-89 CWE-89 High WordPress Plugin OMFG Mobile Pro Cross-Site Scripting (1.1.26) CVE-2014-4541 CWE-79 CWE-79 High WordPress Plugin OMGF-Host Google Fonts Locally Multiple Vulnerabilities (4.5.3) CVE-2021-24638 CVE-2021-24639 CWE-22 CWE-264 CWE-22 CWE-264 High WordPress Plugin Omni Secure Files 'upload.php' Arbitrary File Upload (0.1.13) CWE-434 CWE-434 High WordPress Plugin Onclick show popup Cross-Site Scripting (6.5) CWE-79 CWE-79 High WordPress Plugin OneClick Chat to Order Cross-Site Scripting (1.0.4.1) CVE-2022-4760 CWE-79 CWE-79 High WordPress Plugin One Click SSL Cross-Site Request Forgery (1.4.6) CVE-2019-15828 CWE-352 CWE-352 High WordPress Plugin One Click Upsell Funnel for WooCommerce Unspecified Vulnerability (2.0.0) High WordPress Plugin OneLogin SAML SSO Security Bypass (2.2.0) CWE-287 CWE-287 High WordPress Plugin OneLogin SAML SSO Unspecified Vulnerability (2.1.8) High WordPress Plugin One page checkout and layouts for woocommerce Unspecified Vulnerability (2.7) High WordPress Plugin OnePress Social Locker Multiple Cross-Site Scripting Vulnerabilities (4.2.0) CWE-79 CWE-79 High WordPress Plugin OnePress Social Locker Multiple Unspecified Vulnerabilities (4.2.5) High WordPress Plugin OneSignal-Web Push Notifications Cross-Site Scripting (1.17.7) CVE-2019-15827 CWE-79 CWE-79 High WordPress Plugin One User Avatar-User Profile Picture Multiple Vulnerabilities (2.3.6) CVE-2021-24672 CVE-2021-24675 CWE-79 CWE-352 CWE-79 CWE-352 High WordPress Plugin One User Avatar-User Profile Picture Unspecified Vulnerability (2.3.8) High WordPress Plugin Online Hotel Booking System Pro Cross-Site Scripting (1.1) CVE-2020-15536 CWE-79 CWE-79 High WordPress Plugin Online Hotel Booking System Pro SQL Injection (1.0) CWE-89 CWE-89 High WordPress Plugin Online Lesson Booking Multiple Vulnerabilities (0.8.6) CVE-2019-5972 CVE-2019-5973 CWE-79 CWE-352 CWE-79 CWE-352 High WordPress Plugin On Page SEO + Social Live Chat (Formerly OPS) Cross-Site Scripting (1.0.1) CVE-2021-38332 CWE-79 CWE-79 High WordPress Plugin Ooorl Cross-Site Scripting (1.0.0) CVE-2014-4542 CWE-79 CWE-79 High WordPress Plugin Opal Estate Cross-Site Request Forgery (1.6.11) CWE-352 CWE-352 High WordPress Plugin open-flash-chart-core Remote Code Execution (0.4) CVE-2009-4140 CWE-434 CWE-434 High WordPress Plugin Open Graph for Facebook, Google+ and Twitter Card Tags Cross-Site Scripting (2.2.4) CVE-2018-0579 CWE-79 CWE-79 High WordPress Plugin Open Graph for Facebook, Google+ and Twitter Card Tags Unspecified Vulnerability (2.2.4.1) High WordPress Plugin OpenID Connect Generic Client Cross-Site Scripting (3.8.1) CVE-2021-24214 CWE-79 CWE-79 High WordPress Plugin Opening Hours Cross-Site Scripting (2.3.0) CVE-2022-4752 CWE-79 CWE-79 High WordPress Plugin OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) Cross-Site Scripting (1.1.1) CVE-2024-30450 CWE-79 CWE-79 High WordPress Plugin OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) Supply Chain Attack [Polyfill.io] (1.1.2) CWE-1372 CWE-1372 High WordPress Plugin OPS Old Post Spinner 'ops_file' Parameter Local File Include (2.2.1) CWE-22 CWE-22 High WordPress Plugin Optimize images ALT Text (alt tag) & names for SEO using AI Cross-Site Request Forgery (2.0.7) CVE-2022-4548 CWE-352 CWE-352 High WordPress Plugin OptionTree Cross-Site Scripting (2.5.3) CWE-79 CWE-79 High WordPress Plugin OptionTree Cross-Site Scripting (2.5.5) CWE-79 CWE-79 High WordPress Plugin OptionTree PHP Object Injection (2.6.0) CVE-2019-15319 CWE-915 CWE-915 High WordPress Plugin OptionTree PHP Object Injection (2.7.2) CVE-2019-15320 CVE-2019-15321 CWE-915 CWE-915 High WordPress Plugin oQey Gallery 'gal_id' Parameter SQL Injection (0.4.8) CWE-89 CWE-89 High WordPress Plugin oQey Gallery 'tbpv_domain' Parameter Cross-Site Scripting (0.2) CWE-79 CWE-79 High WordPress Plugin oQey Headers 'oqey_settings.php' SQL Injection (0.3) CWE-89 CWE-89 High WordPress Plugin Orbit Fox by ThemeIsle Multiple Vulnerabilities (2.10.2) CWE-79 CWE-264 CWE-79 CWE-264 High WordPress Plugin Order Export & Order Import for WooCommerce Cross-Site Request Forgery (1.6.0) CWE-352 CWE-352 High WordPress Plugin Order Export & Order Import for WooCommerce Information Disclosure (1.0.8) CWE-200 CWE-200 High WordPress Plugin Order XML File Export Import for WooCommerce Cross-Site Request Forgery (1.3.0) CWE-352 CWE-352 High WordPress Plugin Organizer Multiple Cross-Site Scripting and Information Disclosure Vulnerabilities (1.2.1) CVE-2012-6511 CVE-2012-6512 CWE-79 CWE-200 CWE-79 CWE-200 High WordPress Plugin OSD Subscribe Cross-Site Scripting (1.2.3) CVE-2021-38351 CWE-79 CWE-79 High WordPress Plugin OSM-OpenStreetMap SQL Injection (6.0.2) CVE-2024-3604 CWE-89 CWE-89 High WordPress Plugin Otter-Gutenberg Blocks-Page Builder for Gutenberg Editor & FSE PHAR Deserialization (2.2.5) CVE-2023-2288 CWE-502 CWE-502 High WordPress Plugin Our Team Showcase Cross-Site Request Forgery (1.2) CVE-2014-9523 CWE-352 CWE-352 High WordPress Plugin P3 (Plugin Performance Profiler) Cross-Site Scripting (1.5.3.8) CWE-79 CWE-79 High WordPress Plugin Package Quantity Discount Security Bypass (1.1.2) CWE-264 CWE-264 High WordPress Plugin Page-list Cross-Site Scripting (5.2) CVE-2022-4485 CWE-79 CWE-79 High WordPress Plugin Page and Post Clone Information Disclosure (1.1) CWE-200 CWE-200 High WordPress Plugin Page Animations And Transitions Unspecified Vulnerability (2.1.8) High 1...251252253254...309 252 / 309