Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Sensitive Information Disclosure Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Xss - Known Vulnerabilities Vulnerability Name CVE CWE CWE Severity WordPress Plugin Ultimate Reviews PHP Object Injection (2.0.18) CWE-915 CWE-915 High WordPress Plugin Ultimate Reviews PHP Object Injection (2.1.32) CWE-915 CWE-915 High WordPress Plugin Ultimate SMS Notifications for WooCommerce CSV Injection (1.4.1) CVE-2022-2429 CWE-1236 CWE-1236 High WordPress Plugin ULTIMATE TABLES SQL Injection (1.5) CWE-89 CWE-89 High WordPress Plugin Ultimate Tag Cloud Widget Unspecified Vulnerability (2.3) High WordPress Plugin Ultimate TinyMCE 'swfupload.swf' Cross-Site Scripting (3.5) CVE-2012-3414 CWE-79 CWE-79 High WordPress Plugin Ultimate TinyMCE Multiple Unspecified Vulnerabilities (5.0) High WordPress Plugin ULTIMATE VIDEO GALLERY Cross-Site Scripting (1.4) CWE-79 CWE-79 High WordPress Plugin UltimateWoo-The Ultimate WooCommerce with Unlimited Usage PHP Object Injection (0.1.10) CWE-915 CWE-915 High WordPress Plugin Ultimate WordPress Auction Cross-Site Request Forgery (1.0.0) CWE-352 CWE-352 High WordPress Plugin Ultimate WordPress Auction Multiple Vulnerabilities (4.0.5) CWE-79 CWE-352 CWE-79 CWE-352 High WordPress Plugin Ultimate WP Query Search Filter Cross-Site Scripting (1.0.10) CVE-2023-23832 CWE-79 CWE-79 High WordPress Plugin Ultimeter Security Bypass (1.9.2) CWE-264 CWE-264 High WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.3) CWE-352 CWE-352 High WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.4.1) CVE-2023-23714 CWE-352 CWE-352 High WordPress Plugin Unconfirmed Cross-Site Scripting (1.2.3) CVE-2014-100018 CWE-79 CWE-79 High WordPress Plugin Under Construction, Coming Soon & Maintenance Mode Multiple Vulnerabilities (1.1.1) CWE-79 CWE-918 CWE-79 CWE-918 High WordPress Plugin Under Construction/Maintenance Mode from Acurax Multiple Unspecified Vulnerabilities (2.5.2) High WordPress Plugin underConstruction Cross-Site Request Forgery (1.08) CVE-2013-2699 CWE-352 CWE-352 High WordPress Plugin underConstruction Cross-Site Scripting (1.18) CVE-2021-39320 CWE-79 CWE-79 High WordPress Plugin Under Construction Open Redirect (3.20) CWE-601 CWE-601 High WordPress Plugin Under Construction Unspecified Vulnerability (3.25) High WordPress Plugin Under Construction Unspecified Vulnerability (3.85) High WordPress Plugin UnGallery 'search' Parameter Remote Arbitrary Command Execution (2.1.5) CWE-95 CWE-95 High WordPress Plugin UnGallery Local File Disclosure (1.5.8) CWE-22 CWE-22 High WordPress Plugin Unite Gallery Lite Multiple Vulnerabilities (1.4.6) CWE-89 CWE-352 CWE-89 CWE-352 High WordPress Plugin Universal Analytics Cross-Site Scripting (1.3.0) CWE-79 CWE-79 High WordPress Plugin Universal Post Manager Cross-Site Scripting and SQL Injection Vulnerabilities (1.0.9) CWE-79 CWE-89 CWE-79 CWE-89 High WordPress Plugin Universal Star Rating Unspecified Vulnerability (1.10.3) High WordPress Plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Cross-Site Scripting (1.5.107) CVE-2024-3190 CWE-79 CWE-79 High WordPress Plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Remote Code Execution (1.5.89) CVE-2023-6743 CWE-94 CWE-94 High WordPress Plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) SQL Injection (1.5.107) CVE-2024-4779 CWE-89 CWE-89 High WordPress Plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) SQL Injection (1.5.109) CVE-2024-5329 CWE-89 CWE-89 High WordPress Plugin Unlimited Pop-Ups Multiple Cross-Site Scripting Vulnerabilities (1.4.3) CWE-79 CWE-79 High WordPress Plugin Unlimited PopUps SQL Injection (4.5.3) CVE-2021-24631 CWE-89 CWE-89 High WordPress Plugin Unyson Information Disclosure (2.7.18) CWE-200 CWE-200 High WordPress Plugin Updater by BestWebSoft Cross-Site Scripting (1.34) CVE-2017-2171 CVE-2017-2171 CVE-2017-18565 CWE-79 CWE-79 High WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Request Forgery (1.22.24) CWE-352 CWE-352 High WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Request Forgery (1.23.3) CVE-2023-32960 CWE-352 CWE-352 High WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.9.63) CVE-2015-9360 CWE-79 CWE-79 High WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.13.4) CVE-2017-18593 CWE-79 CWE-79 High WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.16.65) CVE-2021-25022 CWE-79 CWE-79 High WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.16.68) CVE-2021-25089 CWE-79 CWE-79 High WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.22.8) CVE-2022-0864 CWE-79 CWE-79 High WordPress Plugin UpdraftPlus WordPress Backup Multiple Vulnerabilities (1.16.58) CVE-2021-24423 CWE-22 CWE-79 CWE-22 CWE-79 High WordPress Plugin UpdraftPlus WordPress Backup Privilege Escalation (1.23.2) CWE-269 CWE-269 High WordPress Plugin UpdraftPlus WordPress Backup Security Bypass (1.9.50) CWE-264 CWE-264 High WordPress Plugin UpdraftPlus WordPress Backup Security Bypass (1.22.1) CVE-2022-0633 CWE-264 CWE-264 High WordPress Plugin UpiCRM-Free WordPress CRM and Lead Management Information Disclosure (2.1.8.5) CWE-538 CWE-538 High WordPress Plugin Uploader 'num' Parameter Cross-Site Scripting (1.0.0) CWE-79 CWE-79 High WordPress Plugin Uploader 'uploadify.php' Arbitrary File Upload (1.0.4) CWE-434 CWE-434 High WordPress Plugin Uploader Cross-Site Scripting and Arbitrary File Upload Vulnerabilities (1.0.4) CVE-2013-2287 CVE-2013-2288 CWE-79 CWE-434 CWE-79 CWE-434 High WordPress Plugin Upload File Type Settings Cross-Site Scripting (1.1) CVE-2023-25781 CWE-79 CWE-79 High WordPress Plugin Uploadify Integration Multiple Cross-Site Scripting Vulnerabilities (0.9.6) CWE-79 CWE-79 High WordPress Plugin Uploadify Remote File Upload (1.0) CWE-20 CWE-20 High WordPress Plugin UPM Polls 'PID' Parameter SQL Injection (1.0.4) CWE-89 CWE-89 High WordPress Plugin UPM Polls 'qid' Parameter SQL Injection (1.0.3) CWE-89 CWE-89 High WordPress Plugin URL Cloak & Encrypt Cross-Site Scripting (2.0) CVE-2014-4563 CWE-79 CWE-79 High WordPress Plugin Use Any Font Unspecified Vulnerability (4.3.6) High WordPress Plugin User Access Manager Cross-Site Scripting (1.2.6.7) CWE-79 CWE-79 High WordPress Plugin User Access Manager Cross-Site Scripting (1.2.14) CWE-79 CWE-79 High WordPress Plugin User Access Manager Unspecified Vulnerability (1.2.6.9) High WordPress Plugin User Activation Email Cross-Site Scripting (1.3.0) CVE-2021-38325 CWE-79 CWE-79 High WordPress Plugin User Activity Log Multiple Cross-Site Scripting Vulnerabilities (1.4.6) CWE-79 CWE-79 High WordPress Plugin User Activity Log Multiple Vulnerabilities (1.2.4) CWE-79 CWE-352 CWE-79 CWE-352 High WordPress Plugin User Activity Security Bypass (1.0.1) CVE-2022-4550 CWE-290 CWE-290 High WordPress Plugin User Avatar TimThumb Arbitrary File Upload (1.3.7) CVE-2011-4106 CWE-20 CWE-20 High WordPress Plugin User Avatar Unspecified Vulnerability (1.4.6) High WordPress Plugin User Control SQL Injection (2.1.0) CWE-89 CWE-89 High WordPress Plugin User Domain Whitelist Multiple Vulnerabilities (1.4) CWE-79 CWE-352 CWE-79 CWE-352 High WordPress Plugin user files Arbitrary File Upload (2.4.2) CWE-434 CWE-434 High WordPress Plugin User Login History Multiple Cross-Site Scripting Vulnerabilities (1.5.2) CVE-2017-15867 CWE-79 CWE-79 High WordPress Plugin User Login Log Cross-Site Scripting (2.2.2) CWE-79 CWE-79 High WordPress Plugin User Meta 'uploader.php' Arbitrary File Upload (1.1.1) CWE-434 CWE-434 High WordPress Plugin User Meta Manager Information Disclosure (3.4.7) CWE-200 CWE-200 High 1...142143144145...169 143 / 169