Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Registrations for the Events Calendar – Event Registration Plugin | 2.7.5 ~ 2.7.5 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24876.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24822 | Stylish Cost Calculator < 7.04 - Subscriber+ Unauthorised AJAX Calls to Stored XSS | |
| CVE-2017-20008 | myCRED < 1.7.8 - Reflected Cross-Site Scripting | |
| CVE-2021-24745 | About Author Box < 1.0.2 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24748 | Email Before Download < 6.8 - Admin+ SQL Injection | |
| CVE-2021-24749 | URL Shortify < 1.5.1 - Arbitrary Link/Group Deletion via CSRF | |
| CVE-2021-24751 | GenerateBlocks < 1.4.0 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24755 | myCred < 2.3 - Subscriber+ SQL Injection | |
| CVE-2021-24768 | WP RSS Aggregator < 4.19.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24811 | Shop Page WP < 1.2.8 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24927 | My Calendar < 3.2.18 - Subscriber+ Reflected Cross-Site Scripting | |
| CVE-2021-24842 | Bulk Datetime Change < 1.12 - Missing Authorisation | |
| CVE-2021-24860 | BSK PDF Manager < 3.1.2 - Admin+ SQL Injection | |
| CVE-2021-24883 | Popup Anything < 2.0.4 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24889 | Ninja Forms < 3.6.4 - Admin+ SQL Injection | |
| CVE-2021-24899 | Media-Tags <= 3.2.0.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24908 | Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting | |
| CVE-2021-24915 | Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Em | |
| CVE-2021-24918 | Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to S |
No comments yet