CVEs we hold for Western
Records whose assigning authority named Western as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-16614GSheetConnector <= 5.2.1 - Authenticated (Administrator+) SQL Injection via 's' Parameterwesterndeal GSheetConnector – CF7 Google Sheets Connector
CVE-2025-8606GSheetConnector For Gravity Forms <= 1.3.23 - Cross-Site Request Forgery to Arbitrary Plugin Activation/Deactivationwesterndeal GSheetConnector for Gravity Forms – Send…
CVE-2025-8593GSheetConnector For Gravity Forms <= 1.3.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin…westerndeal GSheetConnector for Gravity Forms – Send…
CVE-2025-67979WordPress WPForms Google Sheet Connector plugin <= 4.0.1 - Remote Code Execution (RCE) vulnerabilityWesternDeal WPForms Google Sheet Connector
CVE-2025-67570WordPress WPForms Google Sheet Connector plugin <= 4.0.0 - Broken Access Control vulnerabilityWesternDeal WPForms Google Sheet Connector
CVE-2025-54030WordPress WooCommerce Google Sheet Connector plugin <= 1.3.20 - Cross Site Request Forgery (CSRF) VulnerabilityWesternDeal WooCommerce Google Sheet Connector
CVE-2025-30592WordPress Advanced Dewplayer - plugin <= 1.6 Broken Access Control VulnerabilityWesternDeal Advanced Dewplayer
CVE-2025-22752WordPress GSheetConnector for Forminator Forms Plugin <= 1.0.12 - Reflected Cross Site Scripting (XSS) vulnerabilityWesternDeal GSheetConnector for Forminator Forms
CVE-2025-22686WordPress CF7 Google Sheets Connector plugin <= 5.0.17 - Broken Access Control vulnerabilityWesternDeal CF7 Google Sheets Connector
CVE-2025-13136GSheetConnector For Ninja Forms <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) System Information…westerndeal GSheetConnector For Ninja Forms
CVE-2025-0630Western Telematic Inc NPS Series, DSM Series, CPM Series External Control of File Name or PathWestern Telematic Inc Console Server + PDU Combo Unit (CPM…
CVE-2024-5654CF7 Google Sheets Connector <= 5.0.9 - Missing Authorization to Limited Site Configuration Updatewesterndeal GSheetConnector for CF7 – Connect Contact Form…
CVE-2024-22169Misconfiguration in node.js causing a code execution in WD DiscoveryWestern Digital WD Discovery
CVE-2024-22168Cross-Site Scripting (XSS) vulnerability on Western Digital My Cloud and SanDisk ibi Web AppsWestern Digital My Cloud web app
CVE-2024-1562WooCommerce Google Sheet Connector <= 1.3.11 - Missing Authorizationwesterndeal GSheetConnector for WooCommerce – Send your…
CVE-2023-22819Uncontrolled resource consumption vulnerability in Western Digital My Cloud, My Cloud Home and SanDisk ibi productsWestern Digital My Cloud Home & Duo; SanDisk ibi
CVE-2023-22817Server-side Request Forgery vulnerability in Western Digital My Cloud, My Cloud Home and SanDisk ibi productsWestern Digital My Cloud Home & Duo; SanDisk ibi
CVE-2023-22816Limited Post-Authentication Remote Command Injection in My Cloud ProductsWestern Digital My Cloud OS 5
CVE-2023-22815Post-authentication remote command injection vulnerability on Western Digital My Cloud OS 5 devicesWestern Digital My Cloud OS 5
CVE-2023-22813Device API endpoint missing access controls on Western Digital Mobile and Web AppsWestern Digital My Cloud Home Web App; SanDisk ibi Web App
CVE-2022-36331Impersonation attack causing an Authentication Bypass on Western Digital devicesWestern Digital My Cloud Home and My Cloud Home Duo…
CVE-2022-36330Buffer Overflow Vulnerability in Western Digital My Cloud Home and ibi devicesWestern Digital My Cloud Home and My Cloud Home Duo…
CVE-2022-36329Denial of Service over OTA mechanism in Western Digital My Cloud Home and ibi devicesWestern Digital My Cloud Home and My Cloud Home Duo…
CVE-2022-36328Path Traversal Vulnerability leading to an arbitrary file read in Western Digital devicesWestern Digital My Cloud OS 5
CVE-2022-36327Path traversal vulnerability leading to an arbitrary file write in Western Digital devicesWestern Digital My Cloud OS 5
CVE-2022-36326Resource Exhaustion Vulnerability in Western Digital devicesWestern Digital My Cloud OS 5
CVE-2022-29844Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftpWestern Digital My Cloud
CVE-2022-29843Western Digital My Cloud OS 5 devices Command Injection VulnerabilityWestern Digital My Cloud
CVE-2022-29842Command Injection Vulnerability in Western Digital My Cloud devicesWestern Digital My Cloud OS 5
CVE-2022-29841OS Command Injection vulnerability in Western Digital My Cloud devicesWestern Digital My Cloud OS 5
CVE-2022-29840Server Side Request Forgery Vulnerability in Western Digital My Cloud DevicesWestern Digital My Cloud OS 5
CVE-2022-29838Authentication issue with the encrypted volumes and auto mount feature in My Cloud devicesWestern Digital My Cloud
CVE-2022-29837Path traversal Vulnerability in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi DevicesWestern Digital My Cloud Home; SanDisk ibi
CVE-2022-29836Post-Auth Path Traversal Vulnerability Allows to Custom Package Installation via HTTP APIWestern Digital My Cloud Home; SanDisk ibi
CVE-2022-29835WD Discovery's Use of Weak Hashing Algorithm for Code SigningWestern Digital WD Discovery
CVE-2022-23006Buffer Overflow Vulnerability in Western Digital My Cloud Home Products and SanDisk ibiWestern Digital My Cloud Home Duo; SanDisk ibi
CVE-2022-23004Algorithm incorrectly returning error and Invalid unreduced value written to output bufferWestern Digital Sweet B Library
CVE-2022-23003Shared secret or Point multiplication of NIST P-256 points with X coordinate of zeroWestern Digital Sweet B Library
CVE-2022-23002Point Compression/Decompression of NIST P-256 points with X coordinate of zeroWestern Digital Sweet B Library
CVE-2022-23001Sweet-B Library: Point compress/decompress using the wrong bit for signWestern Digital Sweet B Library
CVE-2022-22998Protecting AWS credentials stored in plaintext on My Cloud HomeWestern Digital My Cloud Home
CVE-2022-22995Western Digital My Cloud OS 5 and My Cloud Home Unauthenticated Arbitrary File Write Vulnerability in NetatalkWestern Digital My Cloud Home
CVE-2022-22994Insufficient Verification of Data Authenticity Remote Code Execution Vulnerability on Western Digital My Cloud devices.Western Digital My Cloud
CVE-2022-22993Limited Server-Side Request Forgery vulnerability on Western Digital My Cloud devices.Western Digital My Cloud
CVE-2022-22991Command injection through unsecured HTTP calls on Western Digital My Cloud devicesWestern Digital My Cloud
CVE-2022-22990Limited authentication bypass vulnerability on Western Digital My Cloud devicesWestern Digital My Cloud
58 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.