6.1

CVSS3.1

CVE-2024-10332 -

A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the endpoint β€œ/abonados/public/janto/main.php”.

πŸ“… Published: Oct. 24, 2024, 12:14 p.m. πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

0.0

CVE-2024-49703 - WordPress WpEvently plugin <= 4.2.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress.This issue affects WpEvently: from n/a through <= 4.2.5.

πŸ“… Published: Oct. 24, 2024, 12:11 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

0.0

CVE-2024-49681 - WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.0.9 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.

πŸ“… Published: Oct. 24, 2024, 12:09 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

0.0

CVE-2024-49691 - WordPress Product Filter by WBW plugin <= 2.7.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW woo-product-filter allows SQL Injection.This issue affects Product Filter by WBW: from n/a through <= 2.7.0.

πŸ“… Published: Oct. 24, 2024, 12:06 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

8.3

CVSS3.1

CVE-2024-5608 - SQL Injection

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.

πŸ“… Published: Oct. 24, 2024, 11:42 a.m. πŸ”„ Last Modified: Nov. 26, 2024, 1:42 a.m.

0.0

CVE-2024-49683 - WordPress Schema & Structured Data for WP & AMP plugin <= 1.3.5 - Sensitive Data Exposure vulnerabi…

Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Schema & Structured Data for WP & AMP: from n/a through <= 1.3.5.

πŸ“… Published: Oct. 24, 2024, 11:37 a.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-49682 - WordPress Simple Membership plugin <= 4.5.3 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allows Phishing.This issue affects Simple Membership: from n/a through <= 4.5.3.

πŸ“… Published: Oct. 24, 2024, 11:36 a.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.4

CVSS3.1

CVE-2024-8959 - WP Adminify – Best WordPress Custom Dashboard Plugin <= 4.0.1.6 - Authenticated (Author+) Stored Cr…

The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authen…

πŸ“… Published: Oct. 24, 2024, 11:34 a.m. πŸ”„ Last Modified: April 8, 2026, 4:58 p.m.

6.4

CVSS3.1

CVE-2024-10176 - Compact WP Audio Player <= 1.9.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via sc…

The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embed_player shortcode in all versions up to, and including, 1.9.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for …

πŸ“… Published: Oct. 24, 2024, 11:03 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

6.1

CVSS3.1

CVE-2024-9214 - Extra Product Options Builder for WooCommerce <= 1.2.133 - Unauthenticated Stored Cross-Site Script…

The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'RednaoSerializedFields' parameter during the creation of a signature file in all versions up to, and including, 1.2.133 due to insufficient input sanitization and output esca…

πŸ“… Published: Oct. 24, 2024, 11:03 a.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.
Total resulsts: 343761
Page 7614 of 34,377
Β« previous page Β» next page
Filters