4.7

CVSS3.1

CVE-2024-8541 - Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO …

The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.5. Th…

πŸ“… Published: Oct. 16, 2024, 2:05 a.m. πŸ”„ Last Modified: April 8, 2026, 4:45 p.m.

6.4

CVSS3.1

CVE-2024-9521 - SEO Manager <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta

The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and…

πŸ“… Published: Oct. 16, 2024, 2:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-48744 -

A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary code via "searchinput" POST request parameter.

πŸ“… Published: Oct. 16, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:47 p.m.

7.2

CVSS3.1

CVE-2024-46213 -

REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.

πŸ“… Published: Oct. 16, 2024, midnight πŸ”„ Last Modified: June 13, 2025, 12:28 a.m.

6.1

CVSS3.1

CVE-2024-48758 -

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code

πŸ“… Published: Oct. 16, 2024, midnight πŸ”„ Last Modified: May 27, 2025, 7:44 p.m.

4.9

CVSS3.1

CVE-2024-46212 -

An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.

πŸ“… Published: Oct. 16, 2024, midnight πŸ”„ Last Modified: June 13, 2025, 6:36 p.m.

5.4

CVSS3.1

CVE-2024-46606 -

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

πŸ“… Published: Oct. 16, 2024, midnight πŸ”„ Last Modified: May 22, 2025, 5:25 p.m.

6.1

CVSS3.1

CVE-2024-46605 -

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

πŸ“… Published: Oct. 16, 2024, midnight πŸ”„ Last Modified: May 22, 2025, 5:25 p.m.

5.3

CVSS3.1

CVE-2024-44762 -

A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.

πŸ“… Published: Oct. 16, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2025, 5:55 p.m.

9.8

CVSS3.1

CVE-2024-48180 -

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

πŸ“… Published: Oct. 16, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 5:34 p.m.
Total resulsts: 349182
Page 8277 of 34,919
Β« previous page Β» next page
Filters