7.7

CVSS3.1

CVE-2025-2271 - IDOR in Issuetrak NewAuditID parameter via Inv_PopTrakXShow.asp

A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insecure Direct Object Reference (IDOR) vulnerability in the Issuetrak audit component. The vulnerability enables unauthorized access to sensitive informat…

πŸ“… Published: March 13, 2025, 6:30 a.m. πŸ”„ Last Modified: March 13, 2025, 7:15 a.m.

2.7

CVSS3.1

CVE-2024-7296 - Incorrect Authorization in GitLab

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

6.5

CVSS3.1

CVE-2025-1257 - Allocation of Resources Without Limits or Throttling in GitLab

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2025-1487 - WoWPth <= 2.0 - Reflected XSS

The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2025-1486 - WoWPth <= 2.0 - Reflected XSS

The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2025-1436 - Limit Bio <= 1.0 - Stored XSS via CSRF

The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2025-1401 - WP Click Info <= 2.7.4 - Reflected XSS

The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2024-13891 - Schedule <= 1.0.0 - Reflected XSS

The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2024-13885 - WP E Customers <= 0.0.1 - Reflected XSS

The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2024-13884 - Limit Bio <= 1.0 - Reflected XSS

The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.
Total resulsts: 285154
Page 2 of 28,516
Β« previous page Β» next page
Filters