| CVE-2024-10861 | Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update | ays-pro | Popup Box – Create Countdown, Coupon, Video, Contact Form Popups | Medium | 5.3 | 2024-11-16 02:02:32 | Deep Dive |
| CVE-2024-10669 | Countdown Timer block – Display the event's date into a timer. <= 1.2.4 - Authenticated (Contributor+) Post Disclosure | bplugins | Countdown Timer Block – Animated Countdown for Events or Launches | Medium | 4.3 | 2024-11-09 04:32:27 | Deep Dive |
| CVE-2024-9884 | T(-) Countdown <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | twinpictures | T(-) Countdown | Medium | 6.4 | 2024-10-30 02:04:33 | Deep Dive |
| CVE-2024-8667 | HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication | nlemsieh | HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce | Medium | 4.3 | 2024-10-24 07:35:57 | Deep Dive |
| CVE-2024-37247 | WordPress jQuery T(-) Countdown Widget plugin <= 2.3.25 - Cross Site Scripting (XSS) vulnerability | twinpictures, baden03 | jQuery T(-) Countdown Widget | Medium | 6.5 | 2024-06-26 21:16:59 | Deep Dive |
| CVE-2024-4384 | CSSable Countdown <= 1.5 - Admin+ Stored XSS | Unknown | CSSable Countdown | 中危 | - | 2024-06-21 06:00:04 | Deep Dive |
| CVE-2024-2017 | Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injection | adamskaat | Countdown, Coming Soon, Maintenance – Countdown & Clock | Medium | 5.4 | 2024-06-06 02:38:14 | Deep Dive |
| CVE-2024-4783 | jQuery T(-) Countdown Widget <= 2.3.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via tminus Shortcode | baden03 | jQuery T(-) Countdown Widget | Medium | 6.4 | 2024-05-23 01:56:19 | Deep Dive |
| CVE-2022-45847 | WordPress Countdown Widget plugin <= 3.1.9.1 - Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) | WPAssist.me | WordPress Countdown Widget | Medium | 6.1 | 2024-03-27 13:48:23 | Deep Dive |
| CVE-2024-1120 | NextMove Lite – Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.17.0 - Missing Authorization to Unauthenticated System Information Disclosure | djeet | Finale Lite – Sales Countdown Timer & Discount for WooCommerce | Medium | 5.3 | 2024-03-01 09:31:41 | Deep Dive |
| CVE-2023-47533 | WordPress Countdown and CountUp, WooCommerce Sales Timer Plugin <= 1.8.2 is vulnerable to Cross Site Scripting (XSS) | wpdevart | Countdown and CountUp, WooCommerce Sales Timer | Medium | 5.9 | 2023-11-14 21:06:44 | Deep Dive |
| CVE-2022-4950 | Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation | narinder-singh | The Events Calendar Events Notification Bar Addon | High | 8.8 | 2023-06-07 01:51:53 | Deep Dive |
| CVE-2023-0171 | jQuery T(-) Countdown Widget < 2.3.24 - Contributor+ Stored XSS | Unknown | jQuery T(-) Countdown Widget | 中危 | - | 2023-02-06 19:59:42 | Deep Dive |
| CVE-2022-3837 | Uji Countdown < 2.3.1 - Admin+ Stored XSS | Unknown | Uji Countdown | 中危 | - | 2022-12-05 16:50:31 | Deep Dive |
| CVE-2022-2245 | Counter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRF | Unknown | Counter Box – WordPress plugin for countdown, timer, counter | 高危 | - | 2022-08-01 12:50:45 | Deep Dive |
| CVE-2020-36526 | Countdown Timer Macro cross site scripting | unspecified | Countdown Timer | Low | 3.5 | 2022-06-03 14:55:25 | Deep Dive |
| CVE-2022-29423 | WordPress Countdown & Clock plugin <= 2.3.2 - Pro Features Lock Bypass vulnerability | Adam Skaat | Countdown & Clock (WordPress plugin) | Low | 3.8 | 2022-05-06 17:40:42 | Deep Dive |
| CVE-2022-29422 | WordPress Countdown & Clock plugin <= 2.3.2 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities | Adam Skaat | Countdown & Clock (WordPress plugin) | Medium | 4.8 | 2022-05-06 17:37:28 | Deep Dive |
| CVE-2022-29421 | WordPress Countdown & Clock plugin <= 2.3.2 - Reflected Cross-Site Scripting (XSS) vulnerability | Adam Skaat | Countdown & Clock (WordPress plugin) | Medium | 4.7 | 2022-05-06 16:58:43 | Deep Dive |
| CVE-2022-29420 | WordPress Countdown & Clock plugin <= 2.3.2 - Auth. Stored Cross-Site Scripting (XSS) vulnerability | Adam Skaat | Countdown & Clock (WordPress plugin) | Medium | 5.9 | 2022-05-06 16:53:31 | Deep Dive |