4.6

CVSS3.1

CVE-2024-45477 - Apache NiFi: Improper Neutralization of Input in Parameter Description

Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which …

πŸ“… Published: Oct. 29, 2024, 9 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:37 a.m.

6.1

CVSS3.1

CVE-2024-49642 - WordPress Todo Custom Field plugin <= 3.0.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi Todo Custom Field todo-custom-field allows Reflected XSS.This issue affects Todo Custom Field: from n/a through <= 3.0.4.

πŸ“… Published: Oct. 29, 2024, 8:50 a.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

4.8

CVSS3.1

CVE-2024-50411 - WordPress WP Abstracts plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.7.1.

πŸ“… Published: Oct. 29, 2024, 8:49 a.m. πŸ”„ Last Modified: April 1, 2026, 4:19 p.m.

0.0

CVE-2024-50412 - WordPress Conditional Fields for Contact Form 7 plugin <= 2.4.15 - Cross Site Scripting (XSS) vuln…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Conditional Fields for Contact Form 7 cf7-conditional-fields allows Stored XSS.This issue affects Conditional Fields for Contact Form 7: from n/a through <= 2.4.15.

πŸ“… Published: Oct. 29, 2024, 8:48 a.m. πŸ”„ Last Modified: April 1, 2026, 4:19 p.m.

0.0

CVE-2024-50413 - WordPress Import and export users and customers plugin <= 1.27.5 - Cross Site Scripting (XSS) vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Stored XSS.This issue affects Import and export users and customers: from n/a through <= 1.27.5.

πŸ“… Published: Oct. 29, 2024, 8:47 a.m. πŸ”„ Last Modified: April 1, 2026, 4:19 p.m.

0.0

CVE-2024-50414 - WordPress Button contact VR plugin <= 4.7.9.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Buttonizer Button contact VR button-contact-vr allows Stored XSS.This issue affects Button contact VR: from n/a through <= 4.7.9.1.

πŸ“… Published: Oct. 29, 2024, 8:47 a.m. πŸ”„ Last Modified: April 1, 2026, 4:19 p.m.

0.0

CVE-2024-50415 - WordPress Ads.txt & App-ads.txt Manager for WordPress plugin <= 1.1.7.1 - Stored Cross Site Scripti…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup Ads.txt & App-ads.txt Manager for WordPress app-ads-txt allows Stored XSS.This issue affects Ads.txt & App-ads.txt Manager for WordPress: from n/a through <= 1.1.7.1.

πŸ“… Published: Oct. 29, 2024, 8:46 a.m. πŸ”„ Last Modified: April 1, 2026, 4:19 p.m.

0.0

CVE-2024-50418 - WordPress Time Slot plugin <= 1.3.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Time Slot Booking Time Slot timeslot allows DOM-Based XSS.This issue affects Time Slot: from n/a through <= 1.3.6.

πŸ“… Published: Oct. 29, 2024, 8:44 a.m. πŸ”„ Last Modified: April 1, 2026, 4:19 p.m.

4.8

CVSS3.1

CVE-2024-50426 - WordPress Survey Maker plugin <= 5.0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.0.2.

πŸ“… Published: Oct. 29, 2024, 8:43 a.m. πŸ”„ Last Modified: April 1, 2026, 4:19 p.m.

0.0

CVE-2024-50475 - WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability

Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a through <= 1.0.

πŸ“… Published: Oct. 29, 2024, 8:39 a.m. πŸ”„ Last Modified: April 1, 2026, 4:19 p.m.
Total resulsts: 343929
Page 7578 of 34,393
Β« previous page Β» next page
Filters