Ulisting
Vendor:
First CVE: Sep 27, 2021 · Active for 4 years
18
Total CVEs
More Total CVEs than 93% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ulisting over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 27, 2021
4 years ago
Most Recent CVE
Mar 15, 2025
499 days ago
CVE Severity & Scoring
Ulisting18 CVEs
33%
33%
33%
All CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (77.8%)
Unknown0 (0.0%)
Required4 (22.2%)
Privileges Required
Low3 (16.7%)
High1 (5.6%)
None14 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36879CRITICAL Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration. | Sep 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-36880CRITICAL Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom. | Sep 27, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-4370CRITICAL The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is sel | Jun 7, 2023 | 9.8 | 28 | NO | NO |
CVE-2021-4343CRITICAL The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_ | Jun 7, 2023 | 9.8 | 28 | NO | NO |
CVE-2021-4341CRITICAL The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm | Jun 7, 2023 | 9.8 | 28 | NO | NO |
CVE-2021-4381CRITICAL The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout:: | Jun 7, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-1657HIGH The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability chec | Mar 15, 2025 | 8.8 | 26 | NO | NO |
CVE-2025-1653HIGH The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_li | Mar 15, 2025 | 8.8 | 26 | NO | NO |
CVE-2021-36874HIGH Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5). | Sep 27, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-4340HIGH The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the | Jun 7, 2023 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Ulisting
Top CWEs
Versions
No cataloged versions.