Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Post Grid plugin before 2.1.8 contains a reflected cross-site scripting vulnerability. The slider import search feature and tab parameter of thesettings are not properly sanitized before being output back in the pages, | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24488.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24473 | User Profile Picture < 2.6.0 - Arbitrary User Picture Change/Deletion via IDOR | |
| CVE-2021-24444 | TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24371 | RSVPMaker < 8.7.3 - Authenticated (admin+) SSRF | |
| CVE-2021-24425 | myStickymenu < 2.5.2 - Authenticated Stored XSS | |
| CVE-2021-24428 | RSS for Yandex Turbo <= 1.30 - Authenticated Stored XSS | |
| CVE-2021-24430 | Speed Booster Pack 4.2.0-beta - Authenticated (admin+) RCE | |
| CVE-2021-24443 | Youzify < 1.0.7 - Stored Cross-Site Scripting via Biography | |
| CVE-2021-24448 | Profile Builder < 3.4.8 - Authenticated Stored XSS | |
| CVE-2021-24450 | ProfilePress < 3.1.8 - Authenticated Stored XSS | |
| CVE-2021-24455 | Tutor LMS < 1.9.2 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24464 | YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSS | |
| CVE-2021-24468 | Leaflet Map < 3.0.0 - Contributor+ Stored XSS | |
| CVE-2021-24470 | Yada Wiki < 3.4.1 - Contributor+ Stored XSS | |
| CVE-2021-24504 | WP LMS <= 1.1.2 - Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24474 | Awesome Weather Widget <= 3.0.2 - Reflected Cross-site Scripting (XSS) | |
| CVE-2021-24476 | Steam Group Viewer <= 2.1 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24477 | Migrate Users <= 1.0.1 - CSRF to Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24478 | Bookshelf <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24479 | DrawBlog <= 0.90 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24480 | Event Geek <= 2.5.2 - Stored Cross-site Scripting (XSS) |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet