Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Car Repair Services & Auto Mechanic | 4.0 ~ 4.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Car Repair Services & Auto Mechanic before 4.0 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the serviceestimatekey parameter before outputting it back in the page. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24335.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24328 | WP Login Security and History <= 1.0 - CSRF to Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24329 | WP Super Cache < 1.7.3 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24330 | Funnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google | |
| CVE-2021-24331 | Smooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSS | |
| CVE-2021-24333 | Content Copy Protection & Prevent Image Save <= 1.3 - CSRF to Stored Cross-Site Scripting | |
| CVE-2021-24334 | Instant Images WordPress Plugin < 4.4.0.1 - Authenticated Stored XSS & XFS | |
| CVE-2021-24313 | WP Prayer < 1.6.2 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24309 | Weekly Schedule < 3.4.3 - Authenticated Stored XSS | |
| CVE-2021-24311 | External Media < 1.0.34 - Authenticated Arbitrary File Upload |
No comments yet