LiquidWeb records
11 published records for vendor liquidweb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 45.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2019-16120No exploit | CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Expoliquidweb · event tickets · CWE-1236 | High8.8 | — | 3.2% | Sep 8, 2019 |
30Monitor | CVE-2023-47668Proof of concept | WordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data Exposureliquidweb · restrict content · CWE-200 | High7.5 | — | 1.0% | Nov 22, 2023 |
30Monitor | CVE-2025-14844No exploit | Membership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposureliquidweb · restrict content · CWE-639 | High7.5 | — | 0.5% | Jan 16, 2026 |
30Monitor | CVE-2024-11090No exploit | Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposureliquidweb · restrict content · CWE-200 | High7.5 | — | 0.5% | Jan 26, 2025 |
26Monitor | CVE-2024-1316No exploit | Event Tickets and Registration < 5.8.1 - Contributor+ Arbitrary Events Accessliquidweb · event tickets · CWE-284 | Medium6.5 | — | 0.6% | Mar 4, 2024 |
24Monitor | CVE-2022-45825No exploit | WordPress WPComplete Plugin <= 2.9.4 is vulnerable to Cross Site Scripting (XSS)liquidweb · wpcomplete · CWE-79 | Medium6.1 | — | 0.5% | Mar 28, 2023 |
24Monitor | CVE-2023-3182No exploit | Membership Plugin - Restrict Content < 3.2.3 - Reflected XSSliquidweb · restrict content · CWE-79 | Medium6.1 | — | 0.5% | Jul 17, 2023 |
21Monitor | CVE-2024-31432No exploit | WordPress Restrict Content plugin <= 3.2.8 - Broken Access Control vulnerabilitystellarwp · restrict content · CWE-862 | Medium5.3 | — | 0.4% | Apr 15, 2024 |
21Monitor | CVE-2024-13457No exploit | Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposureliquidweb · event tickets · CWE-284 | Medium5.3 | — | 0.3% | Jan 30, 2025 |
17Monitor | CVE-2024-1319No exploit | Event Tickets Plus < 5.9.1 - Contributor+ Attendees Lists Disclosureliquidweb · event tickets · CWE-284 | Medium4.3 | — | 0.5% | Mar 4, 2024 |
17Monitor | CVE-2024-1053No exploit | Event Tickets and Registration <= 5.8.1 - Missing Authorizationliquidweb · event tickets · CWE-284 | Medium4.3 | — | 0.4% | Feb 22, 2024 |
- CVE-2019-1612036Monitor
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Expo
HighCVSS 8.8No exploitEPSS 3%liquidweb · event ticketsSep 8, 2019
- CVE-2023-4766830Monitor
WordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5Proof of conceptEPSS 1%liquidweb · restrict contentNov 22, 2023
- CVE-2025-1484430Monitor
Membership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposure
HighCVSS 7.5No exploitEPSS 0%liquidweb · restrict contentJan 16, 2026
- CVE-2024-1109030Monitor
Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
HighCVSS 7.5No exploitEPSS 0%liquidweb · restrict contentJan 26, 2025
- CVE-2024-131626Monitor
Event Tickets and Registration < 5.8.1 - Contributor+ Arbitrary Events Access
MediumCVSS 6.5No exploitEPSS 1%liquidweb · event ticketsMar 4, 2024
- CVE-2022-4582524Monitor
WordPress WPComplete Plugin <= 2.9.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 1%liquidweb · wpcompleteMar 28, 2023
- CVE-2023-318224Monitor
Membership Plugin - Restrict Content < 3.2.3 - Reflected XSS
MediumCVSS 6.1No exploitEPSS 0%liquidweb · restrict contentJul 17, 2023
- CVE-2024-3143221Monitor
WordPress Restrict Content plugin <= 3.2.8 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%stellarwp · restrict contentApr 15, 2024
- CVE-2024-1345721Monitor
Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure
MediumCVSS 5.3No exploitEPSS 0%liquidweb · event ticketsJan 30, 2025
- CVE-2024-131917Monitor
Event Tickets Plus < 5.9.1 - Contributor+ Attendees Lists Disclosure
MediumCVSS 4.3No exploitEPSS 0%liquidweb · event ticketsMar 4, 2024
- CVE-2024-105317Monitor
Event Tickets and Registration <= 5.8.1 - Missing Authorization
MediumCVSS 4.3No exploitEPSS 0%liquidweb · event ticketsFeb 22, 2024