vciy

CVEs we hold for Givewp

Records whose assigning authority named Givewp as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-85530GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization MismatchUnknown GiveWP
CVE-2026-14319GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information DisclosureUnknown GiveWP
CVE-2026-14318GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template SettingsUnknown GiveWP
CVE-2026-14317GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction BypassUnknown GiveWP
CVE-2024-11921Give < 3.19.0 - Reflected XSSUnknown GiveWP
CVE-2023-51415WordPress GiveWP Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS)GiveWP – Donation Plugin and Fundraising Platform
CVE-2023-41665WordPress GiveWP plugin <= 2.33.0 - GiveWP Manager+ Privilege Escalation vulnerabilityGiveWP
CVE-2023-32513WordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object InjectionGiveWP – Donation Plugin and Fundraising Platform
CVE-2023-25450WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Request Forgery (CSRF)GiveWP – Donation Plugin and Fundraising Platform
CVE-2023-23668WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS)GiveWP
CVE-2023-22719WordPress GiveWP Plugin <= 2.25.1 is vulnerable to CSV InjectionGiveWP
CVE-2023-0224GiveWP < 2.24.1 - Unauthenticated SQLiUnknown GiveWP
CVE-2022-4448GiveWP < 2.24.0 - Contributor+ Stored XSSUnknown GiveWP
CVE-2022-40312WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Server Side Request Forgery (SSRF)GiveWP – Donation Plugin and Fundraising Platform
CVE-2022-40211WordPress GiveWP plugin <= 2.25.1 - Cross Site Scripting (XSS) via render_dropdown vulnerabilityGiveWP
CVE-2022-31475WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerabilityGiveWP (WordPress plugin)
CVE-2022-28700WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerabilityGiveWP (WordPress plugin)
CVE-2022-2260GiveWP < 2.21.3 - DoS via CSRFUnknown GiveWP – Donation Plugin and Fundraising Platform
CVE-2022-2215GiveWP < 2.21.3 - Admin+ Stored Cross-Site ScriptingUnknown GiveWP – Donation Plugin and Fundraising Platform
CVE-2022-0252Give < 2.17.3 - Reflected Cross-Site Scripting via Import ToolUnknown GiveWP – Donation Plugin and Fundraising Platform
CVE-2021-25100Give < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms DashboardUnknown GiveWP – Donation Plugin and Fundraising Platform
CVE-2021-25099Give < 2.17.3 - Unauthenticated Reflected Cross-Site ScriptingUnknown GiveWP – Donation Plugin and Fundraising Platform
CVE-2021-24524GiveWP < 2.12.0 - Authenticated Stored XSSUnknown GiveWP – Donation Plugin and Fundraising Platform
CVE-2021-24315Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS)GiveWP – Donation Plugin and Fundraising Platform
CVE-2021-24213GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)GiveWP – Donation Plugin and Fundraising Platform

25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.