5.4

CVSS3.1

CVE-2024-49693 - WordPress Mega Elements – Addons for Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega Elements mega-elements-addons-for-elementor allows Stored XSS.This issue affects Mega Elements: from n/a through <= 1.2.6.

πŸ“… Published: Oct. 24, 2024, 12:41 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

5.4

CVSS3.1

CVE-2024-49695 - WordPress WP Flow Plus plugin <= 5.2.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.3.

πŸ“… Published: Oct. 24, 2024, 12:38 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.4

CVSS3.1

CVE-2024-10180 - Contact Form 7 - Repeatable Fields <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Script…

The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's field_group shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

πŸ“… Published: Oct. 24, 2024, 12:32 p.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.

4.8

CVSS3.1

CVE-2024-49696 - WordPress Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.21 - Cross Site Scriptin…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 3.2.21.

πŸ“… Published: Oct. 24, 2024, 12:29 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

5.4

CVSS3.1

CVE-2024-49702 - WordPress myCred Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred Elementor mycred-for-elementor allows Stored XSS.This issue affects myCred Elementor: from n/a through <= 1.2.6.

πŸ“… Published: Oct. 24, 2024, 12:28 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-10332 -

A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the endpoint β€œ/abonados/public/janto/main.php”.

πŸ“… Published: Oct. 24, 2024, 12:14 p.m. πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

0.0

CVE-2024-49703 - WordPress WpEvently plugin <= 4.2.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress.This issue affects WpEvently: from n/a through <= 4.2.5.

πŸ“… Published: Oct. 24, 2024, 12:11 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

0.0

CVE-2024-49681 - WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.0.9 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.

πŸ“… Published: Oct. 24, 2024, 12:09 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

0.0

CVE-2024-49691 - WordPress Product Filter by WBW plugin <= 2.7.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW woo-product-filter allows SQL Injection.This issue affects Product Filter by WBW: from n/a through <= 2.7.0.

πŸ“… Published: Oct. 24, 2024, 12:06 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

8.3

CVSS3.1

CVE-2024-5608 - SQL Injection

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.

πŸ“… Published: Oct. 24, 2024, 11:42 a.m. πŸ”„ Last Modified: Nov. 26, 2024, 1:42 a.m.
Total resulsts: 343746
Page 7612 of 34,375
Β« previous page Β» next page
Filters