🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
Web Application Vulnerabilities
This page lists
24342 vulnerabilities
in
62 categories
.
Critical: 1593
High: 13071
Medium: 8734
Low: 875
Information: 69
Vulnerability Name
CVE
CWE
Severity
WordPress Plugin Limit Attempts by BestWebSoft Cross-Site Scripting (1.1.7)
CVE-2017-2171
CWE-79
High
WordPress Plugin Limit Attempts by BestWebSoft Multiple Vulnerabilities (1.0.3)
-
CWE-352
High
WordPress Plugin Limit Attempts by BestWebSoft SQL Injection (1.1.0)
-
CWE-89
High
WordPress Plugin Limit Login Attempts Cross-Site Scripting (1.7.1)
CVE-2023-1912
CWE-79
High
WordPress Plugin Limit Login Attempts Cross-Site Scripting (4.0.43)
CVE-2021-24657
CWE-79
High
WordPress Plugin Limit Login Attempts Reloaded Cross-Site Scripting (2.15.2)
CVE-2020-35589
CWE-79
High
WordPress Plugin Limit Login Attempts Reloaded Cross-Site Scripting (2.7.0)
-
CWE-79
High
WordPress Plugin Limit Login Attempts Reloaded Security Bypass (2.17.3)
CVE-2020-35590
CWE-264
High
WordPress Plugin Limit Login Attempts Reloaded Security Bypass (2.7.4)
-
CWE-264
High
WordPress Plugin Limit Login Attempts Security Bypass (1.7.0)
-
CWE-264
High
WordPress Plugin Lingotek Translation Multiple Cross-Site Scripting Vulnerabilities (1.1.8)
-
CWE-79
High
WordPress Plugin Link Juice Keeper Cross-Site Scripting (2.0.2)
CVE-2023-25793
CWE-79
High
WordPress Plugin Link Library 'id' Parameter Cross-Site Scripting and SQL Injection Vulnerabilities (5.0.8)
-
CWE-89
High
WordPress Plugin Link Library 'searchll' Parameter SQL Injection (5.2.1)
-
CWE-89
High
WordPress Plugin Link Library Cross-Site Scripting (5.8.10.6)
-
CWE-79
High
WordPress Plugin Link Library Cross-Site Scripting (5.9.12.29)
-
CWE-79
High
WordPress Plugin Link Library Cross-Site Scripting (5.9.5.5)
-
CWE-79
High
WordPress Plugin Link Library SQL Injection (5.9.13.26)
-
CWE-89
High
WordPress Plugin Link Log-external link click monitor SQL Injection (2.0)
CVE-2015-9344
CWE-89
High
WordPress Plugin Link Optimizer Lite Cross-Site Request Forgery (1.4.5)
CVE-2022-2540
CWE-352
High
WordPress Plugin link-list-manager Cross-Site Scripting (1.0)
CVE-2021-39311
CWE-79
High
WordPress Plugin LinkedIn by BestWebSoft Cross-Site Scripting (1.0.4)
CVE-2017-18516
CWE-79
High
WordPress Plugin LionScripts:IP Blocker Lite Cross-Site Request Forgery (10.3)
-
CWE-352
High
WordPress Plugin LIQUID SPEECH BALLOON Cross-Site Scripting (1.0.6)
CVE-2019-17070
CWE-79
High
WordPress Plugin LISL Last-Image Slider TimThumb Arbitrary File Upload (1.0)
CVE-2011-4106
CWE-20
High
WordPress Plugin List Pages Shortcode Cross-Site Scripting (1.7.4)
CVE-2022-4757
CWE-79
High
WordPress Plugin Listing, Classified Ads & Business Directory-uListing Arbitrary File Upload (1.2.1)
-
CWE-434
High
WordPress Plugin Listing, Classified Ads & Business Directory-uListing Cross-Site Request Forgery (2.0.8)
-
CWE-352
High
WordPress Plugin Listing, Classified Ads & Business Directory-uListing Multiple Vulnerabilities (1.6.6)
-
CWE-264
High
WordPress Plugin Listing, Classified Ads & Business Directory-uListing Multiple Vulnerabilities (2.0.5)
CVE-2021-36879
CWE-352
High
WordPress Plugin Listing, Classified Ads & Business Directory-uListing SQL Injection (2.0.3)
CVE-2021-36880
CWE-89
High
WordPress Plugin ListingPro Local File Inclusion (2.9.3)
CVE-2024-39619
CWE-22
High
WordPress Plugin ListingPro SQL Injection (2.9.3)
CVE-2024-38795
CWE-89
High
WordPress Plugin LiteSpeed Cache Cross-Site Scripting (3.6)
CVE-2020-29172
CWE-79
High
WordPress Plugin LittleBot ACH for Stripe + Plaid Unspecified Vulnerability (1.2.6)
-
-
High
WordPress Plugin Live Chat for Fanpage Cross-Site Scripting (2.0.1)
CVE-2021-24435
CWE-79
High
WordPress Plugin Live Chat Unlimited Cross-Site Scripting (2.8.3)
-
CWE-79
High
WordPress Plugin Live Chat with Facebook Messenger Cross-Site Scripting (1.4.4)
-
CWE-79
High
WordPress Plugin Live Chat-Live support Cross-Site Request Forgery (3.1.0)
CVE-2020-5642
CWE-352
High
WordPress Plugin Live Comment Preview Cross-Site Scripting (2.0.2)
-
CWE-79
High
WordPress Plugin Live Forms-Visual Form Builder SQL Injection (3.0.1)
-
CWE-89
High
WordPress Plugin Live Product Editor for WooCommerce Security Bypass (4.6.2)
-
CWE-264
High
WordPress Plugin Live Scores for SportsPress Multiple Vulnerabilities (1.9.0)
-
CWE-79
High
WordPress Plugin Live Search for WooCommerce Security Bypass (2.0.2)
-
CWE-264
High
WordPress Plugin LiveChat-WP live chat Cross-Site Scripting (3.7.3)
-
CWE-79
High
WordPress Plugin Livefyre Comments 3 Cross-Site Scripting (4.1.4)
-
CWE-79
High
WordPress Plugin LiveGrounds 'uid' Parameter Cross-Site Scripting (0.42)
-
CWE-79
High
WordPress Plugin Livemesh Addons for Elementor Multiple Cross-Site Scripting Vulnerabilities (6.7.1)
CVE-2021-24260
CWE-79
High
WordPress Plugin Livemesh Addons for Elementor Security Bypass (2.5.2)
-
CWE-264
High
WordPress Plugin Livemesh SiteOrigin Widgets Security Bypass (2.5.1)
-
CWE-264
High
WordPress Plugin LiveSig 'wp-root' Parameter Remote File Include (0.4)
-
CWE-94
High
WordPress Plugin Loan Comparison Multiple Cross-Site Scripting Vulnerabilities (1.5.2)
CVE-2023-0442
CWE-79
High
WordPress Plugin Local Market Explorer 'api-key' Parameter Cross-Site Scripting (3.1.1)
-
CWE-79
High
WordPress Plugin Local Weather Cross-Site Scripting (1.0)
CVE-2014-4561
CWE-79
High
WordPress Plugin Localize My Post Local File Inclusion (1.0)
CVE-2018-16299
CWE-22
High
WordPress Plugin Location Weather Cross-Site Scripting (1.3.3)
CVE-2023-0360
CWE-79
High
WordPress Plugin Locations Cross-Site Request Forgery (3.2.1)
-
CWE-352
High
WordPress Plugin Locatoraid Store Locator Cross-Site Request Forgery (3.9.11)
CVE-2023-25709
CWE-352
High
WordPress Plugin Lockdown WP Admin Unspecified Vulnerability (1.1.2)
-
-
High
WordPress Plugin Loco Translate Local File Inclusion (2.2.1)
-
CWE-22
High
WordPress Plugin Loco Translate PHP Code Injection (2.5.3)
CVE-2021-24721
CWE-95
High
WordPress Plugin Loco Translate Unspecified Vulnerability (2.5.4)
-
-
High
WordPress Plugin Log Emails Information Disclosure (1.0.6)
-
CWE-200
High
WordPress Plugin Log HTTP Requests Cross-Site Scripting (1.3.1)
CVE-2022-3402
CWE-79
High
WordPress Plugin LOGIN AND REGISTRATION ATTEMPTS LIMIT Cross-Site Request Forgery (2.1)
CVE-2022-47138
CWE-352
High
WordPress Plugin Login as User or Customer Cross-Site Request Forgery (1.9)
-
CWE-352
High
WordPress Plugin Login as User or Customer Privilege Escalation (3.2)
CVE-2022-4305
CWE-269
High
WordPress Plugin Login as User or Customer Security Bypass (1.7)
-
CWE-264
High
WordPress Plugin Login Block IPs Cross-Site Request Forgery (1.0.0)
CVE-2022-3098
CWE-352
High
WordPress Plugin Login by Auth0 Cross-Site Scripting (3.11.2)
CVE-2019-20173
CWE-79
High
WordPress Plugin Login by Auth0 Multiple Vulnerabilities (3.11.3)
CVE-2020-7948
CWE-352
High
WordPress Plugin Login Logout Menu Cross-Site Scripting (1.3.3)
CVE-2022-4622
CWE-79
High
WordPress Plugin Login Logout Menu Multiple Cross-Site Scripting Vulnerabilities (1.3.3)
CVE-2022-4625
CWE-79
High
WordPress Plugin Login No Captcha reCAPTCHA Security Bypass (1.4.1)
-
CWE-264
High
WordPress Plugin Login No Captcha reCAPTCHA Security Bypass (1.6.11)
CVE-2022-2913
CWE-264
High
«
1
...
258
259
260
...
325
»