Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In June 2021
The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users
CVSS Score
7.2
EPSS Score
0.006
Published
2021-06-07
The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.
CVSS Score
8.8
EPSS Score
0.006
Published
2021-06-07
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.
CVSS Score
7.5
EPSS Score
0.832
Published
2021-06-07
The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.
CVSS Score
6.1
EPSS Score
0.023
Published
2021-06-07
The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, leading to an authenticated Stored Cross-Site Scripting issue
CVSS Score
4.8
EPSS Score
0.004
Published
2021-06-07
The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+) Stored Cross-Site scripting issues
CVSS Score
4.8
EPSS Score
0.004
Published
2021-06-07
PageLayer before 1.3.5 allows reflected XSS via color settings.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-06-07
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-06-07
Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
CVSS Score
5.4
EPSS Score
0.18
Published
2021-06-07
An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an attacker to craft a malicious URL that executes a JavaScript payload in a victim's browser.
CVSS Score
6.1
EPSS Score
0.006
Published
2021-06-07


Contact Us

Shodan ® - All rights reserved