6.1

CVSS3.1

CVE-2024-11273 - Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (foโ€ฆ

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 15, 2025, 7:05 p.m.

6.1

CVSS3.1

CVE-2024-11272 - Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (foโ€ฆ

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 15, 2025, 7:06 p.m.

6.1

CVSS3.1

CVE-2024-10703 - Registrations for The Events Calendar < 2.13.4 - Admin+ Stored XSS

The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in mulโ€ฆ

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 15, 2025, 7:07 p.m.

6.1

CVSS3.1

CVE-2024-10679 - Quiz and Survey Master (QSM) < 9.2.1 - Author+ Stored XSS

The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setโ€ฆ

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 6, 2025, 8 p.m.

4.1

CVSS3.1

CVE-2024-10638 - Product Labels For Woocommerce < 1.5.11 - Admin+ SQLi

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 5, 2025, 3:17 p.m.

6.1

CVSS3.1

CVE-2024-10566 - Slider by 10Web < 1.2.62 - Contributor+ Stored XSS

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 4:45 p.m.

6.1

CVSS3.1

CVE-2024-10565 - Slider by 10Web < 1.2.62 - Admin+ Stored XSS via Widget

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 2, 2025, 5:38 p.m.

6.9

CVSS4.0

CVE-2025-2738 - PHPGurukul Old Age Home Management System manage-scdetails.php sql injection

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/manage-scdetails.php. The manipulation of the argument namesc leads to sql injection. The attack can be initiated remotely. The exโ€ฆ

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 6, 2025, 7:35 p.m.

3.5

CVSS3.1

CVE-2024-10560 - Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 3, 2025, 5:37 p.m.

3.5

CVSS3.1

CVE-2024-10554 - WP-Advanced-Search < 3.3.9.3 - Admin+ Stored XSS

The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite seโ€ฆ

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 15, 2025, 7:18 p.m.
Total resulsts: 346087
Page 5914 of 34,609
ยซ previous page ยป next page
Filters