Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 2.2.1 vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2019-19134
The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript withi...
Heroplugins Hero Maps Premium
383
VMScore
CVE-2018-16206
Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Ohtanz Spam-byebye
383
VMScore
CVE-2014-100008
Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and previous versions for WordPress allows remote malicious users to inject arbitrary web script or HTML via the path parameter...
Joomlaskin Js Multi Hotel
383
VMScore
CVE-2013-7419
Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the roomid parameter.
Joomlaskin Js Multi Hotel 2.2.1
383
VMScore
CVE-2014-6313
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin prior to 2.2.3 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin/admin.php.
Woothemes Woocommerce Plugin 2.2.1
Woothemes Woocommerce Plugin 2.1.9
Woothemes Woocommerce Plugin 2.1.10
Woothemes Woocommerce Plugin 2.1.0
Woothemes Woocommerce Plugin 2.1.11
Woothemes Woocommerce Plugin 2.1.8
Woothemes Woocommerce Plugin 2.1.5
Woothemes Woocommerce Plugin 2.1.3
Woothemes Woocommerce Plugin 2.1.6
Woothemes Woocommerce Plugin 2.1.2
Woothemes Woocommerce Plugin 2.2.0
Woothemes Woocommerce Plugin 2.1.4
Woothemes Woocommerce Plugin 2.1.12
Woothemes Woocommerce Plugin
Woothemes Woocommerce Plugin 2.1.7
Woothemes Woocommerce Plugin 2.1.1
383
VMScore
CVE-2013-1407
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin prior to 5.3.5 and Events Manager Pro plugin prior to 2.2.9 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, ...
Netweblogic Events Manager
Netweblogic Events Manager 5.3.2.1
Netweblogic Events Manager 5.3.1
Netweblogic Events Manager 5.3.2
Netweblogic Events Manager 5.3.3
Netweblogic Events Manager 5.3
Netweblogic Events Manager Pro
Netweblogic Events Manager Pro 2.2.5
Netweblogic Events Manager Pro 2.2.3
Netweblogic Events Manager Pro 2.2.8
Netweblogic Events Manager Pro 2.2.2
Netweblogic Events Manager Pro 2.2.1
Netweblogic Events Manager Pro 2.2.6
Netweblogic Events Manager Pro 2.2.4
Netweblogic Events Manager Pro 2.2
383
VMScore
CVE-2010-5294
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress prior to 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH c...
Wordpress Wordpress 2.8.5.2
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.8.6
Wordpress Wordpress 2.0
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 2.1
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.8.4
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.2
Wordpress Wordpress 2.1.3
Wordpress Wordpress 3.0
Wordpress Wordpress 2.8
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.7.1
Wordpress Wordpress 2.6.3
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.8.3
383
VMScore
CVE-2010-5295
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress prior to 3.0.2 might allow remote malicious users to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
Wordpress Wordpress 2.8.5.2
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.8.6
Wordpress Wordpress 2.0
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 2.1
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.8.4
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.2
Wordpress Wordpress 2.1.3
Wordpress Wordpress 3.0
Wordpress Wordpress 2.8
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.7.1
Wordpress Wordpress 2.6.3
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.8.3
383
VMScore
CVE-2013-6342
Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin prior to 4.0.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php.
Tweet-blender Tweet-blender 3.2.2
Tweet-blender Tweet-blender 2.0.1
Tweet-blender Tweet-blender 3.3.9
Tweet-blender Tweet-blender 3.3.6
Tweet-blender Tweet-blender 3.3.15
Tweet-blender Tweet-blender 3.1.5
Tweet-blender Tweet-blender 3.0.1
Tweet-blender Tweet-blender 3.3.7
Tweet-blender Tweet-blender 3.1.12
Tweet-blender Tweet-blender 3.3.4
Tweet-blender Tweet-blender 2.4.6
Tweet-blender Tweet-blender 3.3.5
Tweet-blender Tweet-blender 3.1.7
Tweet-blender Tweet-blender 2.0.5
Tweet-blender Tweet-blender 3.3.13
Tweet-blender Tweet-blender 2.4.5
Tweet-blender Tweet-blender 3.1.8
Tweet-blender Tweet-blender 3.0.4
Tweet-blender Tweet-blender 2.3.0
Tweet-blender Tweet-blender 3.3.8
Tweet-blender Tweet-blender 3.1.10
Tweet-blender Tweet-blender 3.1.11
383
VMScore
CVE-2013-0236
Multiple cross-site scripting (XSS) vulnerabilities in WordPress prior to 3.5.1 allow remote malicious users to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
Wordpress Wordpress 2.8.5.2
Wordpress Wordpress
Wordpress Wordpress 1.2.3
Wordpress Wordpress 3.4.0
Wordpress Wordpress 2.0.11
Wordpress Wordpress 1.3.3
Wordpress Wordpress 2.8.6
Wordpress Wordpress 2.0
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 1.6.2
Wordpress Wordpress 2.1
Wordpress Wordpress 1.1.1
Wordpress Wordpress 1.2.4
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.8.4
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.2
Wordpress Wordpress 1.2.1
Wordpress Wordpress 2.1.3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
malicious code
XML injection
CVE-2024-28020
CVE-2024-35252
CVE-2024-5833
CVE-2024-30066
injection
CVE-2024-23282
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »