Claudio Viviani

98
All Time Ranking
25
All Time Discoveries

Showing 1-20 of 25 Vulnerabilities

Title CVE ID CVSS Vector Date
WP Fast Cache <= 1.4 - Cross-Site Request Forgery to Cross-Site Scripting 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H May 11, 2015
NEX-Forms – Ultimate Form Builder – Contact forms and much more < 3.4 - SQL Injection 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 21, 2015
AJAX Store Locator <= 1.2 - SQL Injection 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 16, 2015
WORDPRESS VIDEO GALLERY <= 2.8 - SQL Injection 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 13, 2015
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 12, 2015
Duplicator <= 0.5.14 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H April 10, 2015
WORDPRESS VIDEO GALLERY <= 3.0 - Improper Access Control 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L April 5, 2015
Website Contact Form With File Upload < 1.4 - Arbitrary File Upload 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H April 1, 2015
Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H March 14, 2015
Wordpress Video Gallery <= 2.7 - SQL Injection CVE-2015-2065 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H February 12, 2015
WP Symposium <= 14.11 - Arbitrary File Upload CVE-2014-10021 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H December 11, 2014
Ajax Store Locator <= 1.2 - Arbitrary File Download 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N December 7, 2014
wpDataTables <= 1.5.3 - Arbitrary File Upload 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H November 25, 2014
wpDataTables (Premium) <= 1.5.3 - SQL Injection CVE-2014-9175 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H November 23, 2014
Calendar Event Multi View < 1.0.2 - SQL Injection CVE-2014-8586 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H October 23, 2014
Gallery Objects <= 0.4 - SQL Injection CVE-2014-5201 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H September 19, 2014
Spider Facebook <= 1.0.8 - SQL Injection 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H September 7, 2014
Image Gallery - Responsive Photo Gallery <= 1.0.7 - SQL Injection CVE-2014-7153 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H September 2, 2014
GB Gallery Slideshow <= 1.5 - SQL Injection CVE-2014-8375 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L August 11, 2014
Gmedia Photo Gallery < 1.2.2 - Arbitrary File Upload 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H August 2, 2014

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation