CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “awesome”

126 vulnerabilities found for “awesome”

Page 1 of 7

CVE-2024-10148
MEDIUM6.4

The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

sohelwpexpert / awesome_buttons
Network
Published Oct 25, 2024
Page 1 of 7
CVE-2024-37206
HIGH7.1

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme4Press Demo Awesome allows Reflected XSS.This issue affects Demo Awesome: from n/a through 1.0.1.

theme4press / demo_awesome
Network
Published Jul 22, 2024
CVE-2024-0594
HIGH8.8

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

getawesomesupport / awesome_support
Network
Published Feb 10, 2024
CVE-2022-3829
MEDIUM4.8

The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

newnine / font_awesome_4_menus
Network
Published Jan 16, 2024
CVE-2023-51538
MEDIUM4.3

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.5.

getawesomesupport / awesome_support
Network
Published Jan 5, 2024
CVE-2023-48323
MEDIUM4.3

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

getawesomesupport / awesome_support
Network
Published Nov 30, 2023
CVE-2023-5352
MEDIUM4.3

The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.

getawesomesupport / awesome_support
Network
Published Nov 6, 2023
CVE-2023-5354
MEDIUM6.1

The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

getawesomesupport / awesome_support
Network
Published Nov 6, 2023
CVE-2023-5355
HIGH8.1

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

getawesomesupport / awesome_support
Network
Published Nov 6, 2023
CVE-2023-46077
HIGH7.1

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions.

arrowplugins / the_awesome_feed
Network
Published Oct 26, 2023
CVE-2023-44264
MEDIUM6.5

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions.

arrowplugins / the_awesome_feed
Network
Published Oct 2, 2023
CVE-2023-4944
MEDIUM6.4

The Awesome Weather Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' shortcode in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

awesome_weather_widget_project / awesome_weather_widget
Network
Published Sep 14, 2023
CVE-2023-4718
MEDIUM6.4

The Font Awesome 4 Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fa' and 'fa-stack' shortcodes in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

newnine / font_awesome_4_menus
Network
Published Sep 2, 2023
CVE-2022-3511
MEDIUM6.5

The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

getawesomesupport / awesome_support
Network
Published Nov 28, 2022
CVE-2022-36791
MEDIUM5.4

Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Awesome UG Torro Forms plugin <= 1.0.16 at WordPress.

awesome / torro_forms
Network
Published Sep 23, 2022
CVE-2022-38073
MEDIUM5.4

Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress.

getawesomesupport / awesome_support
Network
Published Sep 21, 2022
CVE-2022-37423
HIGH7.5

Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.

neo4j / awesome_procedures_on_cypher+1
Network
Published Aug 12, 2022
CVE-2014-0156
CRITICAL9.8

Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.

manageiq / awesomespawn
Network
Published Jun 30, 2022
CVE-2021-36919
MEDIUM6.1

Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee).

getawesomesupport / awesome_support
Network
Published Nov 26, 2021
CVE-2021-24474
MEDIUM6.1

The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.

awesome_weather_widget_project / awesome_weather_widget
Network
Published Aug 2, 2021