CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “goto”

6 vulnerabilities found for “goto”

CVE-2023-45832
MEDIUM5.9

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions.

northernbeacheswebsites / wp_gotowebinar
Network
Published Oct 25, 2023
CVE-2023-0369
MEDIUM5.4

The GoToWP WordPress plugin through 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

gotowp / gotowp
Network
Published Mar 20, 2023
CVE-2018-25032
HIGH7.5

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

nokogiri / nokogiri+60
Network
Published Mar 25, 2022
CVE-2021-24297
MEDIUM6.1

The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

boostifythemes / goto
Network
Published May 24, 2021
CVE-2021-24314
CRITICAL9.8

The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

boostifythemes / goto
Network
Published May 17, 2021
CVE-2021-24235
MEDIUM6.1

The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.

boostifythemes / goto
Network
Published Apr 22, 2021