8.6

CVSS4.0

CVE-2025-0422 - Authenticated Remote Code Execution via ScriptVar

An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the application. (Remote Code Execution) For this, the user must be able to create "ScriptVars" with the type „script" and preview them by, for example, creating a new "Info". By defaul…

📅 Published: Feb. 18, 2025, 7:57 a.m. 🔄 Last Modified: Feb. 18, 2025, 3:05 p.m.

6.4

CVSS3.1

CVE-2024-13575 - Web Stories Enhancer – Level Up Your Web Stories <= 1.3 - Authenticated (Contributor+) Stored Cross…

The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'web_stories_enhancer' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. …

📅 Published: Feb. 18, 2025, 7:28 a.m. 🔄 Last Modified: April 8, 2026, 5:35 p.m.

6.1

CVSS3.1

CVE-2025-0864 - Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.6.6 - Reflected Cro…

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in all versions up to, and including, 1.0.6.6 due to insufficient input sanitization and output escaping. This makes i…

📅 Published: Feb. 18, 2025, 7:28 a.m. 🔄 Last Modified: April 8, 2026, 5:34 p.m.

4.3

CVSS3.1

CVE-2024-13795 - Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactiv…

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticate…

📅 Published: Feb. 18, 2025, 7:28 a.m. 🔄 Last Modified: April 8, 2026, 5:32 p.m.

6.4

CVSS3.1

CVE-2024-13465 - aBlocks – WordPress Gutenberg Blocks <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scri…

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Table Of Content" Block, specifically in the "markerView" attribute, in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping. This makes…

📅 Published: Feb. 18, 2025, 7:28 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

6.4

CVSS3.1

CVE-2024-11895 - Online Payments – Get Paid with PayPal, Square & Stripe <= 3.20.0 - Authenticated (Contributor+) St…

The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i…

📅 Published: Feb. 18, 2025, 7:28 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

7.2

CVSS3.1

CVE-2024-13704 - Super Testimonials <= 4.0.1 - Unauthenticated Stored Cross-Site Scripting

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

📅 Published: Feb. 18, 2025, 7:28 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

6.1

CVSS3.1

CVE-2024-11376 - s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Sub…

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114…

📅 Published: Feb. 18, 2025, 7:28 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.

6.1

CVSS3.1

CVE-2024-13523 - MemorialDay <= 1.0.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts …

📅 Published: Feb. 18, 2025, 7:02 a.m. 🔄 Last Modified: April 8, 2026, 5:10 p.m.

7.3

CVSS3.1

CVE-2024-57964 - Insecure Loading of Dynamic Link Libraries in HVAC Energy Saving Program

Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects HVAC Energy Saving Program:.

📅 Published: Feb. 18, 2025, 6:33 a.m. 🔄 Last Modified: Feb. 18, 2025, 3:50 p.m.
Total resulsts: 343923
Page 6176 of 34,393
« previous page » next page
Filters