4.3

CVSS3.1

CVE-2024-30457 - WordPress MDTF plugin <= 1.3.3.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.1.

πŸ“… Published: March 29, 2024, 1:06 p.m. πŸ”„ Last Modified: April 28, 2026, 4:09 p.m.

4.3

CVSS3.1

CVE-2024-30458 - WordPress FOX – Currency Switcher Professional for WooCommerce plugin <= 1.4.1.7 - Cross Site Reque…

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.

πŸ“… Published: March 29, 2024, 1:05 p.m. πŸ”„ Last Modified: April 28, 2026, 4:09 p.m.

6.5

CVSS3.1

CVE-2024-30483 - WordPress Sponsors plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorships Sponsors allows Stored XSS.This issue affects Sponsors: from n/a through 3.5.1.

πŸ“… Published: March 29, 2024, 1:03 p.m. πŸ”„ Last Modified: April 28, 2026, 4:09 p.m.

7.1

CVSS3.1

CVE-2024-30503 - WordPress Mailster plugin <= 4.0.6 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster mailster.This issue affects Mailster: from n/a through <= 4.0.6.

πŸ“… Published: March 29, 2024, 1:02 p.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

6.5

CVSS3.1

CVE-2024-30519 - WordPress Lordicon Animated Icons plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lordicon Lordicon Animated Icons allows Stored XSS.This issue affects Lordicon Animated Icons: from n/a through 2.0.1.

πŸ“… Published: March 29, 2024, 1:01 p.m. πŸ”„ Last Modified: April 28, 2026, 4:09 p.m.

6.5

CVSS3.1

CVE-2024-30520 - WordPress Carousel Anything For WPBakery Page Builder plugin <= 2.1 - Cross Site Scripting (XSS) vu…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Carousel Anything For WPBakery Page Builder allows Stored XSS.This issue affects Carousel Anything For WPBakery Page Builder: from n/a through 2.1.

πŸ“… Published: March 29, 2024, 1 p.m. πŸ”„ Last Modified: April 28, 2026, 4:09 p.m.

5.5

CVSS3.1

CVE-2024-3078 - Qdrant Full Snapshot REST API snapshots.rs path traversal

A vulnerability was found in Qdrant up to 1.6.1/1.7.4/1.8.2 and classified as critical. This issue affects some unknown processing of the file lib/collection/src/collection/snapshots.rs of the component Full Snapshot REST API. The manipulation leads to path traversal. Upgrading to version 1.8.3 is …

πŸ“… Published: March 29, 2024, 12:31 p.m. πŸ”„ Last Modified: May 7, 2025, 4:29 p.m.

9.8

CVSS3.1

CVE-2023-6191 - SQLi in WebPDKS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egehan Security WebPDKS allows SQL Injection.This issue affects WebPDKS: through 20240329.Β NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

πŸ“… Published: March 29, 2024, 11:40 a.m. πŸ”„ Last Modified: April 10, 2025, 6:55 p.m.

6.1

CVSS3.1

CVE-2023-6047 - Reflected XSS in Algoritim E-commerce Software

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Algoritim E-commerce Software allows Reflected XSS.This issue affects E-commerce Software: before 3.9.2.

πŸ“… Published: March 29, 2024, 11:35 a.m. πŸ”„ Last Modified: March 19, 2025, 2:28 p.m.

7.5

CVSS3.1

CVE-2024-2848 - Responsive <= 5.0.2 - Missing Authorization to HTML Injection

The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_footer_text_callback function in all versions up to, and including, 5.0.2. This makes it possible for unauthenticated attackers to inject arbitrary HTML content into t…

πŸ“… Published: March 29, 2024, 11:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 10513 of 34,919
Β« previous page Β» next page
Filters