6.1

CVSS3.1

CVE-2024-9375 - WordPress Captcha Plugin by Captcha Bank <= 4.0.36 - Reflected Cross-Site Scripting

The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.0.36. This makes it possible for unauthenticated attackers to inject arbi…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

6.1

CVSS3.1

CVE-2024-9204 - Smart Custom 404 Error Page <= 11.4.7 - Reflected Cross-Site Scripting

The Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all versions up to, and including, 11.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:09 p.m.

6.4

CVSS3.1

CVE-2024-9421 - Login Logout Shortcode <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via clas…

The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:06 p.m.

6.4

CVSS3.1

CVE-2024-9368 - Aggregator Advanced Settings <= 1.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG…

The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level acces…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:04 p.m.

6.1

CVSS3.1

CVE-2024-9349 - Auto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.2 - Reflected Cross-Site Scripting

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.4.2. This makes it possible for unauthenticated attackers t…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

6.4

CVSS3.1

CVE-2024-9372 - WP Blocks Hub <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

6.1

CVSS3.1

CVE-2024-9353 - Popularis Extra <= 1.2.6 - Reflected Cross-Site Scripting

The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to inject arbitrary w…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 4:52 p.m.

6.1

CVSS3.1

CVE-2024-9345 - Product Delivery Date for WooCommerce – Lite <= 2.7.3 - Reflected Cross-Site Scripting

The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to inject a…

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.

6.1

CVSS3.1

CVE-2024-8802 - Clio Grow <= 1.0.2 - Reflected Cross-Site Scripting

The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that …

πŸ“… Published: Oct. 4, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

6.1

CVSS3.1

CVE-2024-47854 -

An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.

πŸ“… Published: Oct. 4, 2024, midnight πŸ”„ Last Modified: Oct. 17, 2025, 3:15 p.m.
Total resulsts: 349182
Page 8405 of 34,919
Β« previous page Β» next page
Filters