6.4

CVSS3.1

CVE-2025-1406 - Newpost Catch <= 1.3.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via npc Shortcode

The Newpost Catch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's npc shortcode in all versions up to, and including, 1.3.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

📅 Published: Feb. 21, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 7:23 p.m.

6.4

CVSS3.1

CVE-2025-1407 - AMO Team Showcase <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via amoteam_s…

The AMO Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's amoteam_skills shortcode in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: Feb. 21, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.

6.4

CVSS3.1

CVE-2024-13672 - Mini Course Generator | Embed mini-courses and interactive content <= 1.0.5 - Authenticated (Contri…

The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mcg' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attribute…

📅 Published: Feb. 21, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

6.4

CVSS3.1

CVE-2024-13379 - C9 Admin Dashboard <= 1.3.5 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uplo…

The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abov…

📅 Published: Feb. 21, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

5.3

CVSS3.1

CVE-2024-13818 - Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profil…

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log files. This makes …

📅 Published: Feb. 21, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

4.3

CVSS3.1

CVE-2024-13883 - WPUpper Share Buttons <= 3.51 - Cross-Site Request Forgery to Custom CSS Update

The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. This is due to missing or incorrect nonce validation on the 'save_custom_css_request' function. This makes it possible for unauthenticated attackers to inject custo…

📅 Published: Feb. 21, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

6.5

CVSS3.1

CVE-2024-13235 - Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.4 - Authenticated (Subscriber+) SQ…

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing S…

📅 Published: Feb. 21, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-13388 - TCBD Tooltip <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: Feb. 21, 2025, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 4:49 p.m.

4.9

CVSS3.1

CVE-2024-38657 -

External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.

📅 Published: Feb. 21, 2025, 1:25 a.m. 🔄 Last Modified: July 9, 2025, 2:50 p.m.

5.7

CVSS4.0

CVE-2025-1001 - Medixant RadiAnt DICOM Viewer Improper Certificate Validation

Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle attack (MITM). An attacker could modify the server's response and deliver a malic…

📅 Published: Feb. 21, 2025, 12:48 a.m. 🔄 Last Modified: Feb. 21, 2025, 9:28 p.m.
Total resulsts: 344055
Page 6154 of 34,406
« previous page » next page
Filters