0.0

CVE-2024-50490 - WordPress PegaPoll plugin <= 1.0.2 - Arbitrary Option Update to Privilege Escalation vulnerability

Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.

📅 Published: Oct. 29, 2024, 8:33 a.m. 🔄 Last Modified: April 1, 2026, 4:19 p.m.

0.0

CVE-2024-50420 - WordPress aDirectory plugin <= 1.3 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Shell to a Web Server.This issue affects aDirectory: from n/a through <= 1.3.

📅 Published: Oct. 29, 2024, 8:32 a.m. 🔄 Last Modified: April 1, 2026, 4:19 p.m.

0.0

CVE-2024-50427 - WordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.

📅 Published: Oct. 29, 2024, 8:31 a.m. 🔄 Last Modified: April 1, 2026, 4:19 p.m.

6.1

CVSS3.1

CVE-2024-10048 - Post Status Notifier Lite and Premium <= 1.11.6 - Reflected Cross-Site Scripting via page

The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.11.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i…

📅 Published: Oct. 29, 2024, 8:31 a.m. 🔄 Last Modified: April 8, 2026, 5:06 p.m.

6.1

CVSS3.1

CVE-2024-9438 - SEUR Oficial <= 2.2.11 - Reflected Cross-Site Scripting

The SEUR Oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'change_service' parameter in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary …

📅 Published: Oct. 29, 2024, 8:31 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

0.0

CVE-2024-50473 - WordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3.

📅 Published: Oct. 29, 2024, 8:30 a.m. 🔄 Last Modified: April 1, 2026, 4:19 p.m.

4.6

CVSS3.1

CVE-2024-46872 - Client-Side Path Traversal Leading to CSRF in Playbooks

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks

📅 Published: Oct. 29, 2024, 8:12 a.m. 🔄 Last Modified: Nov. 8, 2024, 3 p.m.

4.3

CVSS3.1

CVE-2024-47401 - DoS via Amplified GraphQL Response in Playbooks

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sen…

📅 Published: Oct. 29, 2024, 8:11 a.m. 🔄 Last Modified: Sept. 29, 2025, 2:47 p.m.

4.3

CVSS3.1

CVE-2024-50052 - Arbitrary post deletion via Playbooks /ignore-thread endpoint

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.

📅 Published: Oct. 29, 2024, 8:10 a.m. 🔄 Last Modified: Sept. 29, 2025, 2:47 p.m.

4.3

CVSS3.1

CVE-2024-10241 - Private channel names leaked with Ctrl+K when ElasticSearch is enabled

Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.

📅 Published: Oct. 29, 2024, 8:08 a.m. 🔄 Last Modified: Sept. 30, 2025, 5:09 p.m.
Total resulsts: 343926
Page 7579 of 34,393
« previous page » next page
Filters