CVEs we hold for Scott
Records whose assigning authority named Scott as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9189Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment Bypass via Insufficient Verification of Data…scottpaterson Contact Form 7 – PayPal & Stripe Add-on
CVE-2026-66660WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control vulnerabilityScott Paterson Contact Form 7 – PayPal & Stripe Add-on
CVE-2026-65518WordPress Accept Donations with PayPal & Stripe plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerabilityScott Paterson Accept Donations with PayPal & Stripe
CVE-2026-65517WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerabilityScott Paterson Easy PayPal Buy Now Button
CVE-2026-41471Easy PayPal Events & Tickets < 1.4 Information Disclosure via QR Code EndpointScott Paterson easy-paypal-events-tickets
CVE-2026-32834Easy PayPal Events & Tickets < 1.4 Authentication Bypass via QR Code ScanningScott Paterson easy-paypal-events-tickets
CVE-2025-68602WordPress Accept Donations with PayPal plugin <= 1.5.2 - Open Redirection vulnerabilityScott Paterson Accept Donations with PayPal & Stripe
CVE-2025-66107WordPress Subscriptions & Memberships for PayPal plugin <= 1.1.7 - Broken Access Control vulnerabilityScott Paterson Subscriptions & Memberships for PayPal
CVE-2025-49386WordPress Preserve Code Formatting Plugin <= 4.0.1 - PHP Object Injection VulnerabilityScott Reilly Preserve Code Formatting
CVE-2025-49302WordPress Easy Stripe plugin <= 1.1 - Remote Code Execution (RCE) VulnerabilityScott Paterson Easy Stripe
CVE-2025-47623WordPress Easy PayPal Buy Now Button plugin <= 2.0 - Cross Site Scripting (XSS) VulnerabilityScott Paterson Easy PayPal Buy Now Button
CVE-2025-47519WordPress Easy PayPal Events plugin <= 1.2.2 - Cross Site Request Forgery (CSRF) VulnerabilityScott Paterson Easy PayPal Events
CVE-2025-47518WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.3.4 - Cross Site Scripting (XSS) VulnerabilityScott Paterson Contact Form 7 – PayPal & Stripe Add-on
CVE-2025-47517WordPress Accept Donations with PayPal plugin <= 1.4.5 - CSRF to Stored XSS vulnerabilityScott Paterson Accept Donations with PayPal & Stripe
CVE-2025-47516WordPress Time Clock plugin <= 1.2.3 - Cross Site Scripting (XSS) VulnerabilityScott Paterson Time Clock
CVE-2025-39434WordPress Avatar plugin <= 0.1.4 - Insecure Direct Object References (IDOR) vulnerabilityScott Taylor Avatar
CVE-2025-32483WordPress Request Call Back plugin <= 1.4.1 - Cross Site Scripting (XSS) VulnerabilityScott Salisbury Request Call Back
CVE-2025-31468WordPress WP_Identicon plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerabilityscottsm WP_Identicon
CVE-2025-30970WordPress Easy Contact plugin <= 0.1.2 - Reflected Cross Site Scripting (XSS) vulnerabilityscottwallick Easy Contact
CVE-2025-23887WordPress Blog Summary plugin <= 0.1.2 β - Cross Site Scripting (XSS) vulnerabilityscottwallick Blog Summary
CVE-2025-23878WordPress Post-to-Post Links plugin <= 4.2 - Cross Site Scripting (XSS) vulnerabilityScott Reilly Post-to-Post Links
CVE-2025-23445WordPress Easy Tynt plugin <= 0.2.5.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerabilityscottswezey Easy Tynt
CVE-2025-22582WordPress Uptime Robot plugin <= 0.1.3 - CSRF to Stored XSS vulnerabilityScott Nelle Uptime Robot
CVE-2025-22521WordPress wp Hosting Performance Check Plugin <= 2.18.8 - Reflected Cross Site Scripting (XSS) vulnerabilityScott Farrell wp Hosting Performance Check
CVE-2025-1561AppPresser – Mobile App Framework <= 4.4.10 - Unauthenticated Stored Cross-Site Scriptingscottopolis AppPresser – Mobile App Framework
CVE-2025-12752Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creationscottpaterson Subscriptions & Memberships for PayPal
CVE-2025-11881AppPresser – Mobile App Framework <= 4.5.0 - Missing Authorization to Unauthenticated Limited Sensitive Information…scottopolis AppPresser – Mobile App Framework
CVE-2025-10701Time Clock – A WordPress Employee & Volunteer Time Clock Plugin <= 1.3.1 - Authenticated (Custom+) Stored Cross-Site…scottpaterson Time Clock – A WordPress Employee & Volunteer…
CVE-2024-9593Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code ExecutionScott Paterson Time Clock Pro; scottpaterson Time Clock – A…
CVE-2024-9592Easy PayPal Gift Certificate <= 1.2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via…scottpaterson Easy PayPal Gift Certificate
CVE-2024-9305AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTPscottopolis AppPresser – Mobile App Framework
CVE-2024-8476Easy PayPal Events <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletionscottpaterson Easy PayPal Events & Tickets
CVE-2024-51650WordPress Random Featured Post plugin <= 1.1.3 - CSRF to Stored Cross Site Scripting (XSS) vulnerabilityscottmydollarplancom Random Featured Post
CVE-2024-50492WordPress ScottCart plugin <= 1.1 - Remote Code Execution (RCE) vulnerabilityScott Paterson ScottCart
CVE-2024-50475WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerabilityScott Gamon Signup Page
CVE-2024-49318WordPress My Reading Library plugin <= 1.0 - PHP Object Injection vulnerabilityScott My Reading Library
CVE-2024-48021WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerabilityScott Paterson Contact Form 7 – PayPal & Stripe Add-on
CVE-2024-4611AppPresser <= 4.3.2 - Improper Missing Encryption Exception Handling to Authentication Bypassscottopolis AppPresser – Mobile App Framework
CVE-2024-43236WordPress Easy PayPal & Stripe Buy Now Button plugin <= 1.9 - Open Redirection vulnerabilityScott Paterson Easy PayPal Buy Now Button
CVE-2024-32102WordPress Crony Cronjob Manager plugin <= 0.5.0 - Cross Site Request Forgery (CSRF) vulnerabilityScott Kingsley Clark Crony Cronjob Manager
CVE-2024-31374WordPress AppPresser plugin <= 4.3.0 - Cross Site Request Forgery (CSRF) vulnerabilityScott Bolinger AppPresser
CVE-2024-29130WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerabilityScott Paterson Contact Form 7 – PayPal & Stripe Add-on
CVE-2024-27192WordPress Configure SMTP Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS)Scott Reilly Configure SMTP
CVE-2024-1719Easy PayPal & Stripe Buy Now Button <= 1.8.3 & Contact Form 7 – PayPal & Stripe Add-on <= 2.1 - Cross-Site Request…scottpaterson Contact Form 7 – PayPal & Stripe Add-on
CVE-2024-13728Accept Donations with PayPal & Stripe <= 1.4.4 - Reflected Cross-Site Scriptingscottpaterson Accept Donations with PayPal & Stripe
CVE-2024-13560Subscriptions & Memberships for PayPal <= 1.1.6 - Cross-Site Request Forgery to Arbitrary Post Deletionscottpaterson Subscriptions & Memberships for PayPal
CVE-2024-12423Contact Form 7 Redirect & Thank You Page <= 1.0.7 - Reflected Cross-Site Scriptingscottpaterson Business Essentials for Contact Form 7
CVE-2024-11024AppPresser – Mobile App Framework <= 4.4.6 - Unauthenticated Privilege Escalation via Password Resetscottopolis AppPresser – Mobile App Framework
CVE-2024-10685Contact Form 7 Redirect & Thank You Page <= 1.0.6 - Reflected Cross-Site Scriptingscottpaterson Business Essentials for Contact Form 7
CVE-2024-10683Contact Form 7 - PayPal & Stripe Add-on <= 2.3.1 - Reflected Cross-Site Scriptingscottpaterson Contact Form 7 – PayPal & Stripe Add-on
CVE-2023-51683WordPress Easy PayPal Buy Now Button Plugin <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF)Scott Paterson Easy PayPal & Stripe Buy Now Button
CVE-2023-47239WordPress Easy PayPal Shopping Cart Plugin <= 1.1.10 is vulnerable to Cross Site Scripting (XSS)Scott Paterson Easy PayPal Shopping Cart
CVE-2023-45604WordPress Get Custom Field Values Plugin <= 4.0.1 is vulnerable to Cross Site Scripting (XSS)Scott Reilly Get Custom Field Values
CVE-2023-4214AppPresser <= 4.2.5 - Insecure Password Reset Mechanismscottopolis AppPresser – Mobile App Framework
CVE-2023-24405WordPress Contact Form 7 – PayPal & Stripe Add-on Plugin <= 1.9.3 is vulnerable to Cross Site Request Forgery (CSRF)Scott Paterson Contact Form 7 – PayPal & Stripe Add-on
CVE-2023-24395WordPress Contact Form 7 Redirect & Thank You Page Plugin <= 1.0.3 is vulnerable to Cross Site Request Forgery (CSRF)Scott Paterson Contact Form 7 Redirect & Thank You Page
CVE-2022-45360WordPress Commenter Emails Plugin <= 2.6.1 is vulnerable to CSV InjectionScott Reilly Commenter Emails
CVE-2022-31124Possible leak of key's raw field if declared length is incorrect in openssh_key_parserscottcwang openssh_key_parser
63 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.