Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Sensitive Information Disclosure Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Xss - Known Vulnerabilities Vulnerability Name CVE CWE CWE Severity WordPress Resource Management Errors Vulnerability (CVE-2014-5266) CVE-2014-5266 Medium WordPress REST API User Enumeration CWE-200 CWE-200 Low WordPress Same Origin Method Execution (SOME) Vulnerability (0.70 - 3.7.13) CVE-2016-4566 CWE-79 CWE-79 High WordPress Server-Side Request Forgery (3.7 - 6.1.1) CVE-2022-3590 CWE-918 CWE-918 High WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2016-4029) CVE-2016-4029 CWE-918 CWE-918 High WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-9066) CVE-2017-9066 CWE-918 CWE-918 High WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17669) CVE-2019-17669 CWE-918 CWE-918 Critical WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17670) CVE-2019-17670 CWE-918 CWE-918 Critical WordPress Super Socialat backdoor plugin CWE-94 CWE-94 High WordPress Theme OneTone: Unauthenticated Stored Cross-Site Scripting (XSS) CVE-2019-17230 CVE-2019-17231 CWE-79 CWE-79 High WordPress Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2022-3590) CVE-2022-3590 CWE-367 CWE-367 Medium WordPress Ultimate Member Plugin Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2020-6859) CVE-2020-6859 CWE-639 CWE-639 Medium WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10673) CVE-2019-10673 CWE-352 CWE-352 High WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-31216) CVE-2023-31216 CWE-352 CWE-352 High WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-8520) CVE-2024-8520 CWE-352 CWE-352 Medium WordPress Ultimate Member Plugin CVE-2019-10271 Vulnerability (CVE-2019-10271) CVE-2019-10271 Medium WordPress Ultimate Member Plugin CVE-2020-36157 Vulnerability (CVE-2020-36157) CVE-2020-36157 Critical WordPress Ultimate Member Plugin CVE-2020-36170 Vulnerability (CVE-2020-36170) CVE-2020-36170 Medium WordPress Ultimate Member Plugin CVE-2025-0318 Vulnerability (CVE-2025-0318) CVE-2025-0318 Medium WordPress Ultimate Member Plugin Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-3361) CVE-2022-3361 CWE-22 CWE-22 Medium WordPress Ultimate Member Plugin Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-3966) CVE-2022-3966 CWE-22 CWE-22 High WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-8354) CVE-2015-8354 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-9304) CVE-2015-9304 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-10872) CVE-2016-10872 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-0585) CVE-2018-0585 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-6944) CVE-2018-6944 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-13136) CVE-2018-13136 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17866) CVE-2018-17866 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-20965) CVE-2018-20965 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14945) CVE-2019-14945 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14946) CVE-2019-14946 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14947) CVE-2019-14947 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-24306) CVE-2021-24306 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-1208) CVE-2022-1208 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-2123) CVE-2024-2123 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-2765) CVE-2024-2765 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-8519) CVE-2024-8519 CWE-707 CWE-707 Medium WordPress Ultimate Member Plugin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2024-1071) CVE-2024-1071 CWE-138 CWE-138 Critical WordPress Ultimate Member Plugin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2024-12276) CVE-2024-12276 CWE-138 CWE-138 Medium WordPress Ultimate Member Plugin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2025-0308) CVE-2025-0308 CWE-138 CWE-138 High WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36155) CVE-2020-36155 CWE-269 CWE-269 Critical WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36156) CVE-2020-36156 CWE-269 CWE-269 High WordPress Ultimate Member Plugin Missing Authorization Vulnerability (CVE-2024-10528) CVE-2024-10528 CWE-862 CWE-862 Medium WordPress Ultimate Member Plugin Other Vulnerability (CVE-2022-3383) CVE-2022-3383 High WordPress Ultimate Member Plugin Other Vulnerability (CVE-2022-3384) CVE-2022-3384 High WordPress Ultimate Member Plugin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-1209) CVE-2022-1209 CWE-601 CWE-601 Medium WordPress Ultimate Member Plugin Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-10270) CVE-2019-10270 CWE-640 CWE-640 High WordPress Uncontrolled Resource Consumption Vulnerability (CVE-2018-6389) CVE-2018-6389 CWE-400 CWE-400 High WordPress Uncontrolled Resource Consumption Vulnerability (CVE-2023-22622) CVE-2023-22622 CWE-400 CWE-400 High WordPress Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-14028) CVE-2018-14028 CWE-434 CWE-434 High WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-14725) CVE-2017-14725 CWE-601 CWE-601 Medium WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10100) CVE-2018-10100 CWE-601 CWE-601 Medium WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10101) CVE-2018-10101 CWE-601 CWE-601 Medium WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-16220) CVE-2019-16220 CWE-601 CWE-601 Medium WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-4048) CVE-2020-4048 CWE-601 CWE-601 Medium WordPress Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2007-6013) CVE-2007-6013 CWE-327 CWE-327 Critical WordPress Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Vulnerability (CVE-2017-5493) CVE-2017-5493 CWE-338 CWE-338 High WordPress Use of Insufficiently Random Values Vulnerability (CVE-2017-17091) CVE-2017-17091 CWE-330 CWE-330 High WordPress User-Agent SQL Injection Vulnerability (1.5.2) CVE-2006-1012 CWE-89 CWE-89 High WordPress username enumeration CWE-200 CWE-200 Medium WordPress user registration enabled CWE-16 CWE-16 Informational WordPress W3 Total Cache plugin predictable cache filenames CVE-2012-6077 CVE-2012-6078 CVE-2012-6079 CWE-200 CWE-200 High WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2014-6412) CVE-2014-6412 CWE-640 CWE-640 High WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2017-8295) CVE-2017-8295 CWE-640 CWE-640 Medium WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2020-11027) CVE-2020-11027 CWE-640 CWE-640 High WordPress XML-RPC authentication brute force CWE-521 CWE-521 Medium WPEngine _wpeprivate/config.json information disclosure CWE-200 CWE-200 High WP Plugin Contact Form 7 Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2023-6630) CVE-2023-6630 CWE-639 CWE-639 Medium WP Plugin Contact Form 7 CVE-2018-20979 Vulnerability (CVE-2018-20979) CVE-2018-20979 Critical WP Plugin Contact Form 7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-2242) CVE-2024-2242 CWE-707 CWE-707 Medium WP Plugin Contact Form 7 Improper Validation of Integrity Check Value Vulnerability (CVE-2025-3247) CVE-2025-3247 CWE-354 CWE-354 Medium WP Plugin Contact Form 7 Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-2265) CVE-2014-2265 CWE-264 CWE-264 Medium WP Plugin Contact Form 7 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-35489) CVE-2020-35489 CWE-434 CWE-434 Critical WP Plugin Contact Form 7 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-6449) CVE-2023-6449 CWE-434 CWE-434 High WP Plugin Contact Form 7 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-4704) CVE-2024-4704 CWE-601 CWE-601 Medium 1...302303304305...309 303 / 309