Wishlist
This hub aggregates every CVE we track for Wishlist, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
0
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM7HIGH4LOW1
Monthly trend
0
0
0
0
0
1
1
3
2
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 12 most recently published vulnerabilities affecting Wishlist.
- CVE-2025-31061WordPress Wishlist plugin <= 2.1.0 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-49075WordPress Wishlist plugin <= 1.0.43 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2025-31062WordPress Wishlist plugin <= 2.1.0 - Sensitive Data Exposure Vulnerability4.3
- CVE-2025-31063WordPress Wishlist plugin <= 2.1.0 - Broken Access Control Vulnerability4.3
- CVE-2025-24655WordPress Wishlist Plugin <= 1.0.39 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-32618WordPress Wishlist plugin <= 1.0.46 - SQL Injection vulnerability8.5
- CVE-2025-32272WordPress Wishlist plugin <= 1.0.46 - Cross Site Request Forgery (CSRF) vulnerability4.3
- CVE-2024-12809Wishlist <= 1.0.43 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2025-26915WordPress Wishlist Plugin <= 1.0.41 - SQL Injection vulnerability8.5
- CVE-2015-3357Cross-site scripting (XSS) vulnerability in the Wishlist module before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "access wishlists" permission to inje...3.5
- CVE-2015-3354Cross-site request forgery (CSRF) vulnerability in the Wishlist module before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote attackers to hijack the authentication of arbitrary users f...5.8
- CVE-2012-2069Cross-site request forgery (CSRF) vulnerability in the Wishlist module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.6 for Drupal allows remote attackers to hijack the authentication of arbitrary...6.8
Product normalization is registry-driven with AI assist and human review. How it works