6.4

CVSS3.1

CVE-2024-13466 - Automatically Hierarchic Categories in Menu <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Si…

The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This ma…

πŸ“… Published: Jan. 30, 2025, 12:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-13380 - Alex Reservations: Smart Restaurant Booking <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Si…

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po…

πŸ“… Published: Jan. 30, 2025, 12:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2022-43916 - IBM App Connect Enterprise Certified Container improper communications restriction

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, and 12.7 Pods do not restrict network egress for Pods that are used for internal infrastructure.

πŸ“… Published: Jan. 30, 2025, 12:04 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 5:50 p.m.

8.6

CVSS3.1

CVE-2025-0747 - Stored Cross-Site vulnerability in EmbedAI

A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message that will be executed when a user opens the chat.

πŸ“… Published: Jan. 30, 2025, 11:20 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:59 p.m.

6.1

CVSS3.1

CVE-2025-0746 - Reflected Cross-Site Scripting vulnerability in EmbedAI

A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show/<SCRIPT>" endpoint to inject the malicious JavaScript code. This JavaScript code will be executed w…

πŸ“… Published: Jan. 30, 2025, 11:19 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:12 p.m.

7.5

CVSS3.1

CVE-2025-0745 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the database by requesting the "/embedai/app/uploads/database/<SQL_FILE>" endpoint.

πŸ“… Published: Jan. 30, 2025, 11:18 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:12 p.m.

7.5

CVSS3.1

CVE-2025-0744 - Improper Access Control vulnerability in EmbedAI

an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST request changing the parameters of the "/demos/embedai/pmt_cash_on_delivery/pay" endpoint.

πŸ“… Published: Jan. 30, 2025, 11:17 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:18 p.m.

5.3

CVSS3.1

CVE-2025-0743 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint incl…

πŸ“… Published: Jan. 30, 2025, 11:16 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:18 p.m.

5.8

CVSS3.1

CVE-2025-0742 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others users by changing the "FILE_ID" of the endpoint "/embedai/files/show/<FILE_ID>".

πŸ“… Published: Jan. 30, 2025, 11:14 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:18 p.m.

5.8

CVSS3.1

CVE-2025-0741 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message".

πŸ“… Published: Jan. 30, 2025, 11:13 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 4:41 p.m.
Total resulsts: 349182
Page 6911 of 34,919
Β« previous page Β» next page
Filters