6.4

CVSS3.1

CVE-2024-10226 - Arconix Shortcodes <= 2.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via box Sho…

The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

πŸ“… Published: Oct. 29, 2024, 1:53 p.m. πŸ”„ Last Modified: April 8, 2026, 5:09 p.m.

6.4

CVSS3.1

CVE-2024-9505 - Beaver Builder – WordPress Page Builder <= 2.8.4.2 - Authenticated (Contributor+) Stored DOM-Based …

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f…

πŸ“… Published: Oct. 29, 2024, 1:53 p.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

6.1

CVSS3.1

CVE-2024-47640 - WordPress WP ERP plugin <= 1.13.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp allows Reflected XSS.This issue affects WP ERP: from n/a through <= 1.13.2.

πŸ“… Published: Oct. 29, 2024, 1:10 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-49632 - WordPress CWD 3D Image Gallery plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Senthil Vel CWD 3D Image Gallery cwd-3d-image-gallery allows Reflection Injection.This issue affects CWD 3D Image Gallery: from n/a through <= 1.0.

πŸ“… Published: Oct. 29, 2024, 1:09 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-49634 - WordPress BP Member Type Manager plugin <= 1.01 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager bp-member-type-manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through <= 1.01.

πŸ“… Published: Oct. 29, 2024, 1:05 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-49635 - WordPress Banner Slider plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manjurul.cis Banner Slider banner-slider allows Reflected XSS.This issue affects Banner Slider: from n/a through <= 2.1.

πŸ“… Published: Oct. 29, 2024, 1:04 p.m. πŸ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.5

CVSS3.1

CVE-2024-6673 - CSRF Vulnerability in parisneo/lollms-webui

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim int…

πŸ“… Published: Oct. 29, 2024, 12:50 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 8:37 p.m.

9.8

CVSS3.1

CVE-2024-8309 - SQL Injection in langchain-ai/langchain

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant securit…

πŸ“… Published: Oct. 29, 2024, 12:50 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

9.8

CVSS3.1

CVE-2024-7042 - Prompt Injection in langchain-ai/langchainjs Leading to SQL Injection

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all da…

πŸ“… Published: Oct. 29, 2024, 12:50 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

6.5

CVSS3.1

CVE-2024-7472 - Email Injection Vulnerability in lunary-ai/lunary

lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespac…

πŸ“… Published: Oct. 29, 2024, 12:49 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 344963
Page 7673 of 34,497
Β« previous page Β» next page
Filters