🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
/ High Severity
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
High Severity Vulnerabilities
Found
13053 vulnerabilities
at
High
severity.
Vulnerability Name
CVE
CWE
Severity
WordPress Plugin The Post Grid-Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid Cross-Site Request Forgery (5.0.4)
CVE-2022-46853
CWE-352
High
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.2.0)
CVE-2022-4464
CWE-79
High
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.1.6)
CVE-2022-0200
CWE-79
High
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.2.1)
CVE-2023-0362
CWE-79
High
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.1.9)
-
CWE-79
High
WordPress Plugin Timed Content Cross-Site Scripting (2.72)
CVE-2023-0067
CWE-79
High
WordPress Plugin Top 10-Popular posts for WordPress Cross-Site Scripting (3.2.2)
CVE-2022-4570
CWE-79
High
WordPress Plugin Transposh WordPress Translation Multiple Cross-Site Scripting Vulnerabilities (1.0.7)
CVE-2021-24911
CWE-79
High
WordPress Plugin Twenty20 Image Before-After Cross-Site Scripting (1.5.9)
CVE-2022-4580
CWE-79
High
WordPress Plugin User Activity Security Bypass (1.0.1)
CVE-2022-4550
CWE-290
High
WordPress Plugin User Verification Security Bypass (1.0.93)
CVE-2022-4693
CWE-287
High
WordPress Plugin uTubeVideo Gallery Cross-Site Scripting (2.0.7)
CVE-2023-0151
CWE-79
High
WordPress Plugin uTubeVideo Gallery Unspecified Vulnerability (2.0.6)
-
-
High
WordPress Plugin uTubeVideo Gallery Unspecified Vulnerability (2.0.4)
-
-
High
WordPress Plugin Video Conferencing with Zoom Cross-Site Scripting (4.0.9)
CVE-2022-4578
CWE-79
High
WordPress Plugin Video Conferencing with Zoom Cross-Site Scripting (3.9.2)
-
CWE-79
High
WordPress Plugin Video Conferencing with Zoom Cross-Site Scripting (3.8.15)
-
CWE-79
High
WordPress Plugin Video Conferencing with Zoom Information Disclosure (3.8.16)
CVE-2022-0384
CWE-200
High
WordPress Plugin Video Sidebar Widgets Cross-Site Scripting (6.1)
CVE-2022-4785
CWE-79
High
WordPress Plugin Video.js-HTML5 Video Player for Wordpress Cross-Site Scripting (4.5.0)
CVE-2022-4786
CWE-79
High
WordPress Plugin VK All in One Expansion Unit Cross-Site Scripting (9.85.0.1)
CVE-2023-0230
CWE-79
High
WordPress Plugin Watu Quiz Cross-Site Scripting (3.3.8.1)
CVE-2023-0428
CWE-79
High
WordPress Plugin Watu Quiz Cross-Site Scripting (3.3.8.2)
CVE-2023-0429
CWE-79
High
WordPress Plugin Widget Shortcode Cross-Site Scripting (0.3.5)
CVE-2022-4473
CWE-79
High
WordPress Plugin Widgets on Pages Cross-Site Scripting (1.6.0)
CVE-2022-4488
CWE-79
High
WordPress Plugin Word Balloon Cross-Site Scripting (4.19.2)
CVE-2022-4751
CWE-79
High
WordPress Plugin WordPress Gallery-NextGEN Gallery Cross-Site Request Forgery (3.28)
CVE-2022-38468
CWE-352
High
WordPress Plugin WordPress Simple Shopping Cart Cross-Site Scripting (4.6.1)
CVE-2022-4672
CWE-79
High
WordPress Plugin WP Airbnb Review Slider SQL Injection (3.2)
CVE-2023-0262
CWE-89
High
WordPress Plugin WP Customer Area Cross-Site Request Forgery (8.1.3)
CVE-2022-4745
CWE-352
High
WordPress Plugin WP Dark Mode-Best Dark Mode & Social Sharing for WordPress Cross-Site Scripting (3.0.6)
CVE-2022-4714
CWE-79
High
WordPress Plugin WP Font Awesome Cross-Site Scripting (1.7.8)
CVE-2023-0271
CWE-79
High
WordPress Plugin WP FullCalendar Security Bypass (1.4.1)
CVE-2022-3891
CWE-639
High
WordPress Plugin WP Google Review Slider Cross-Site Scripting (11.5)
CVE-2022-4242
CWE-79
High
WordPress Plugin WP Google Review Slider SQL Injection (11.7)
CVE-2023-0259
CWE-89
High
WordPress Plugin WP Helper Premium Cross-Site Scripting (4.2)
CVE-2023-0448
CWE-79
High
WordPress Plugin WP Limit Login Attempts Security Bypass (2.6.4)
CVE-2022-4303
CWE-693
High
WordPress Plugin WP Popups-WordPress Popup builder Cross-Site Scripting (2.1.4.6)
CVE-2022-4716
CWE-79
High
WordPress Plugin WP Private Message Insecure Direct Object Reference (1.0.5)
CVE-2023-0453
CWE-639
High
WordPress Plugin WP Responsive Testimonials Slider And Widget Cross-Site Scripting (1.5)
CVE-2022-4750
CWE-79
High
WordPress Plugin WP Review Slider SQL Injection (10.9)
CVE-2022-0383
CWE-89
High
WordPress Plugin WP Review Slider SQL Injection (12.1)
CVE-2023-0260
CWE-89
High
WordPress Plugin WP Table Builder-WordPress Table Cross-Site Scripting (1.4.6)
CVE-2022-46852
CWE-79
High
WordPress Plugin WP Table Builder-WordPress Table Security Bypass (1.3.15)
-
CWE-862
High
WordPress Plugin WP-TopBar SQL Injection (5.36)
CVE-2023-23824
CWE-89
High
WordPress Plugin WP TripAdvisor Review Slider SQL Injection (10.7)
CVE-2023-0261
CWE-89
High
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Cross-Site Scripting (6.4)
CVE-2022-4656
CWE-79
High
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Security Bypass (5.4)
CVE-2021-25042
CWE-862
High
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (5.5)
CVE-2022-0410
CWE-89
High
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (5.7)
CVE-2022-33965
CWE-89
High
WordPress Plugin WP Yelp Review Slider SQL Injection (7.0)
CVE-2023-0263
CWE-89
High
WordPress Plugin wpDataTables-WordPress Data Table, Dynamic Tables & Table Charts Cross-Site Scripting (2.1.49)
-
CWE-79
High
WordPress Plugin wpDataTables-WordPress Data Table, Dynamic Tables & Table Charts Multiple Cross-Site Scripting Vulnerabilities (2.1.27)
CVE-2022-29432
CWE-79
High
WordPress Plugin WPZOOM Portfolio Cross-Site Scripting (1.2.1)
CVE-2022-4789
CWE-79
High
WordPress Plugin Wufoo Shortcode Cross-Site Scripting (1.51)
CVE-2022-4679
CWE-79
High
WordPress Plugin Wufoo Shortcode Cross-Site Scripting (1.50)
-
CWE-79
High
WordPress Plugin Wufoo Shortcode Cross-Site Scripting (1.47)
-
CWE-79
High
WordPress Plugin YaMaps for WordPress Cross-Site Scripting (0.6.25)
CVE-2023-0270
CWE-79
High
WordPress Plugin YARPP-Yet Another Related Posts Cross-Site Scripting (5.30.2)
CVE-2022-4471
CWE-79
High
WordPress Plugin Youtube Channel Gallery Cross-Site Scripting (2.4)
CVE-2022-4783
CWE-79
High
WordPress Plugin Youtube shortcode Cross-Site Scripting (1.8.5)
CVE-2023-23687
CWE-79
High
WordPress Plugin Youzify-BuddyPress Community, User Profile, Social Network & Membership for WordPress Cross-Site Scripting (1.2.1)
CVE-2023-0059
CWE-79
High
WordPress Plugin Youzify-BuddyPress Community, User Profile, Social Network & Membership for WordPress Cross-Site Scripting (1.0.6)
CVE-2021-24443
CWE-79
High
WordPress Plugin Youzify-BuddyPress Community, User Profile, Social Network & Membership for WordPress SQL Injection (1.1.9)
CVE-2022-1950
CWE-89
High
WordPress Plugin 301 Redirects-Easy Redirect Manager Cross-Site Request Forgery (2.72)
-
CWE-352
High
WordPress Plugin Accept Stripe Donation-AidWP Cross-Site Request Forgery (3.1.5)
CVE-2022-47422
CWE-352
High
WordPress Plugin Accept Stripe Donation-AidWP Security Bypass (2.8)
-
CWE-862
High
WordPress Plugin Advanced Dynamic Pricing for WooCommerce Cross-Site Request Forgery (4.1.3)
CVE-2022-38095
CWE-352
High
WordPress Plugin Advanced Dynamic Pricing for WooCommerce Multiple Vulnerabilities (4.1.5)
CVE-2022-43491
CWE-862
High
WordPress Plugin ALD-Dropshipping and Fulfillment for AliExpress and WooCommerce Multiple Vulnerabilities (1.0.21)
CVE-2022-46811
CWE-862
High
WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic Cross-Site Request Forgery (4.2.3.1)
CVE-2022-38093
CWE-352
High
WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic Multiple Cross-Site Scripting Vulnerabilities (4.2.9)
CVE-2023-0586
CWE-79
High
WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic Multiple Vulnerabilities (4.1.5.2)
CVE-2021-25037
CWE-287
High
WordPress Plugin Archivist-Custom Archive Templates Multiple Vulnerabilities (1.7.4)
CVE-2023-25490
CWE-352
High
WordPress Plugin AutomatorWP-The most flexible and powerful no-code automation for WordPress Cross-Site Request Forgery (2.5.8)
-
CWE-352
High
« Previous
1
...
162
163
164
165
166
167
168
169
...
175
Next »