CVEs

List of Common Vulnerabilities and Exposures (CVEs) and affected websites count. Only CVEs that are detectable from client-side software packages and libraries are included.

ProductCVEWebsites
WordPressWP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding3,568,724
Contact Form 7The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient ...2,545,721
Yoast SEOWordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)2,016,067
SwiperPrototype Pollution1,496,708
WordPressWordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘...1,188,209
PHPSecurity issue with external entity loading in XML without enabling it1,089,606
PHPBuffer overflow and overread in phar_dir_read()1,089,606
WordPressWordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure1,079,839
PHPOOB read due to insufficient input validation in imageloadfont()1,076,326
PHPMissing error check and insufficient random bytes in HTTP Digest authentication for SOAP1,061,221
PHPphar wrapper can occur dos when using quine gzip file1,052,163
PHP$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities1,052,163
PHPSpecial characters break path parsing in XML functions1,044,385
PHPPHP-FPM memory access in root process leading to privilege escalation1,010,879
PHPZipArchive::extractTo may extract outside of destination dir977,161
ElementorWordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS)947,249
PHPFreeing unallocated memory in php_pgsql_free_params()945,201
PHPmysqlnd/pdo password buffer overflow945,201
PHPMultiple vulnerabilities in Firebird client extension922,016
PHPIncorrect URL validation in FILTER_VALIDATE_URL922,016