|
1991
|
9.8 |
CRITICAL
Network
|
-
|
-
|
WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-47940
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1992
|
8.2 |
HIGH
Network
|
-
|
-
|
WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap co…
|
CWE-89
SQL Injection
|
CVE-2021-47941
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1993
|
8.8 |
HIGH
Network
|
-
|
-
|
TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functio…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-47943
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1994
|
5.3 |
MEDIUM
Network
|
-
|
-
|
OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiti…
|
CWE-352
Origin Validation Error
|
CVE-2021-47946
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1995
|
5.4 |
MEDIUM
Network
|
-
|
-
|
WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers…
|
CWE-80
Basic XSS
|
CVE-2021-47948
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1996
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulati…
|
CWE-79
Cross-site Scripting
|
CVE-2021-47950
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1997
|
6.4 |
MEDIUM
Network
|
-
|
-
|
WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access C…
|
CWE-79
Cross-site Scripting
|
CVE-2021-47951
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1998
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick a…
|
CWE-352
Origin Validation Error
|
CVE-2021-47953
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1999
|
8.8 |
HIGH
Network
|
-
|
-
|
Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image parameter. Attackers can up…
|
CWE-94
Code Injection
|
CVE-2022-50944
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2000
|
6.4 |
MEDIUM
Network
|
-
|
-
|
WordPress 3dady real-time web stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input …
|
CWE-79
Cross-site Scripting
|
CVE-2022-50945
|
2026-05-12 23:24 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|