6.1

CVSS3.1

CVE-2024-12725 - Clasify Classified Listing <= 1.0.7 - Reflected XSS

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: June 11, 2025, 5:18 p.m.

6.1

CVSS3.1

CVE-2024-12724 - WP DeskLite <= 1.0.0 - Reflected XSS

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: June 11, 2025, 5:20 p.m.

5.4

CVSS3.1

CVE-2024-12722 - Twitter Bootstrap Collapse aka Accordian Shortcode <= 1.0 - Stored XSS via Shortcode

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Crโ€ฆ

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: June 11, 2025, 5:23 p.m.

4.8

CVSS3.1

CVE-2024-12716 - Simple Basic Contact Form < 20250114 - Admin+ Stored XSS

The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setuโ€ฆ

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: June 11, 2025, 7:57 p.m.

4.8

CVSS3.1

CVE-2024-12680 - Prisna GWT < 1.4.14 - Admin+ Stored XSS

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 3:43 p.m.

4.8

CVSS3.1

CVE-2024-12679 - Prisna GWT < 1.4.14 - Admin+ Stored XSS

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 3:43 p.m.

6.5

CVSS3.1

CVE-2024-12301 - JSP Store Locator <= 1.0 - Deletion via Missing CSRF

The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 6:42 p.m.

6.1

CVSS3.1

CVE-2024-12282 - WordPress่ฟžๆŽฅๅพฎๅš <= 2.5.6 - Stored XSS via CSRF

The WordPress่ฟžๆŽฅๅพฎๅš WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 6:41 p.m.

4.8

CVSS3.1

CVE-2024-11843 - Panorama โ€“ WordPress Project Management Plugin <= 1.5.1 - Admin+ Stored XSS

The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 6:43 p.m.

6.1

CVSS3.1

CVE-2024-11719 - tarteaucitron.js for WordPress < 0.3.0 - Stored XSS via CSRF

The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

๐Ÿ“… Published: May 15, 2025, 8:06 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 6:44 p.m.
Total resulsts: 346536
Page 5131 of 34,654
ยซ previous page ยป next page
Filters