6.1

CVSS3.1

CVE-2024-13705 - StageShow <= 9.8.6 - Reflected Cross-Site Scripting

The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 9.8.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th…

📅 Published: Jan. 30, 2025, 1:41 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:17 p.m.

8.8

CVSS3.1

CVE-2024-13720 - WP Image Uploader <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File De…

The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to delete arbitrary files…

📅 Published: Jan. 30, 2025, 1:41 p.m. 🔄 Last Modified: Jan. 30, 2025, 6:44 p.m.

6.1

CVSS3.1

CVE-2024-13512 - Wonder FontAwesome <= 0.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to update settings and inject malicio…

📅 Published: Jan. 30, 2025, 1:41 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:08 p.m.

6.4

CVSS3.1

CVE-2024-13661 - Table Editor <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Table Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wptableeditor_vtabs' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti…

📅 Published: Jan. 30, 2025, 1:41 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:08 p.m.

6.4

CVSS3.1

CVE-2024-13700 - Embed Swagger UI <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Jan. 30, 2025, 1:41 p.m. 🔄 Last Modified: Jan. 31, 2025, 4:49 p.m.

6.4

CVSS3.1

CVE-2024-12444 - WP Dispensary <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcode in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: Jan. 30, 2025, 1:41 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:45 p.m.

4.3

CVSS3.1

CVE-2024-11583 - Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.9 - Missing …

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_zipped_font' function in all versions up to, and including, 1.5.9. This makes it possible for authenti…

📅 Published: Jan. 30, 2025, 1:41 p.m. 🔄 Last Modified: Jan. 31, 2025, 8:03 p.m.

6.3

CVSS4.0

CVE-2025-0870 - Axiomatic Bento4 Ap4DataBuffer.h GetData heap-based overflow

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of a…

📅 Published: Jan. 30, 2025, 1 p.m. 🔄 Last Modified: Feb. 28, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-0869 - Cianet ONU GW24AC Login cross site scripting

A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Login. The manipulation of the argument browserLang leads to cross site scripting. The attack can be launched remotely. The…

📅 Published: Jan. 30, 2025, 1 p.m. 🔄 Last Modified: Feb. 7, 2025, 5:15 p.m.

6.4

CVSS3.1

CVE-2024-13466 - Automatically Hierarchic Categories in Menu <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Si…

The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This ma…

📅 Published: Jan. 30, 2025, 12:22 p.m. 🔄 Last Modified: July 13, 2025, 11:22 a.m.
Total resulsts: 343040
Page 6296 of 34,304
« previous page » next page
Filters