7

CVSS3.1

CVE-2025-20881 -

Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

πŸ“… Published: Feb. 4, 2025, 7:19 a.m. πŸ”„ Last Modified: Feb. 12, 2025, 1:42 p.m.

4.3

CVSS3.1

CVE-2024-13607 - JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Authenticated (Subscriber+) Insec…

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. This makes it possible for authenticated…

πŸ“… Published: Feb. 4, 2025, 6:41 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-12597 - HT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner…

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticat…

πŸ“… Published: Feb. 4, 2025, 6:41 a.m. πŸ”„ Last Modified: April 8, 2026, 4:37 p.m.

5.3

CVSS3.1

CVE-2025-0466 - Sensei LMS < 4.24.4 - Unauthenticated sensei_email/sensei_message Disclosure

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

πŸ“… Published: Feb. 4, 2025, 6 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 6:16 p.m.

6.1

CVSS3.1

CVE-2025-0368 - Banner Garden Plugin for WordPress <= 0.1.3 - Reflected XSS

The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users.

πŸ“… Published: Feb. 4, 2025, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 6:28 p.m.

6.1

CVSS3.1

CVE-2024-13332 - TransFinanz <= 1.0.0 - Reflected XSS

The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Feb. 4, 2025, 6 a.m. πŸ”„ Last Modified: May 26, 2025, 1:06 a.m.

6.1

CVSS3.1

CVE-2024-13331 - WP Dream Carousel <= 1.0.1b - Reflected XSS

The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Feb. 4, 2025, 6 a.m. πŸ”„ Last Modified: May 13, 2025, 6:53 p.m.

7.1

CVSS3.1

CVE-2024-13330 - Justrows Free <= 0.2 - Reflected XSS

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Feb. 4, 2025, 6 a.m. πŸ”„ Last Modified: May 13, 2025, 6:59 p.m.

7.1

CVSS3.1

CVE-2024-13329 - Solidres <= 0.9.4 - Reflected XSS

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Feb. 4, 2025, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 5:50 p.m.

6.1

CVSS3.1

CVE-2024-13328 - Giga Messenger Bots <= 2.3.1 - Reflected XSS

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Feb. 4, 2025, 6 a.m. πŸ”„ Last Modified: May 13, 2025, 7 p.m.
Total resulsts: 349182
Page 6860 of 34,919
Β« previous page Β» next page
Filters