8.2

CVSS4.0

CVE-2024-7108 - Incorrect Authorization in National Keep's CyberMath

Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.240816253.

πŸ“… Published: Sept. 26, 2024, 12:07 p.m. πŸ”„ Last Modified: Oct. 3, 2024, 12:31 a.m.

6.8

CVSS4.0

CVE-2024-7107 - Directory Traversal in National Keep's CyberMath

Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath: before CYBM.240816253.

πŸ“… Published: Sept. 26, 2024, 12:02 p.m. πŸ”„ Last Modified: Oct. 3, 2024, 12:39 a.m.

5.5

CVSS3.1

CVE-2024-8633 - Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, …

πŸ“… Published: Sept. 26, 2024, 11:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:43 p.m.

6.8

CVSS3.1

CVE-2024-8725 - Advanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Limited File Upload

Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This makes it possible for authenticated attackers, with Subscri…

πŸ“… Published: Sept. 26, 2024, 10:59 a.m. πŸ”„ Last Modified: April 8, 2026, 5:24 p.m.

7.5

CVSS3.1

CVE-2024-8126 - Advanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Arbitrary File Upload

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Admini…

πŸ“… Published: Sept. 26, 2024, 10:59 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

7.2

CVSS3.1

CVE-2024-8704 - Advanced File Manager <= 5.2.8 - Authenticated (Administrator+) Local JavaScript File Inclusion via…

The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary…

πŸ“… Published: Sept. 26, 2024, 10:59 a.m. πŸ”„ Last Modified: April 8, 2026, 4:55 p.m.

5.8

CVSS3.1

CVE-2024-9199 - Rate limit vulnerability in Clibo Manager

Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of service (DoS).

πŸ“… Published: Sept. 26, 2024, 9:50 a.m. πŸ”„ Last Modified: Oct. 2, 2024, 2:33 p.m.

7.6

CVSS3.1

CVE-2024-9198 - Stored Cross-Site Scripting vulnerability in Clibo Manager

Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture.

πŸ“… Published: Sept. 26, 2024, 9:49 a.m. πŸ”„ Last Modified: Oct. 2, 2024, 2:33 p.m.

7.2

CVSS3.1

CVE-2022-4541 - WordPress Visitors <= 1.0 - Unauthenticated Stored Cross-Site Scripting via HTTP Header

The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

πŸ“… Published: Sept. 26, 2024, 9:29 a.m. πŸ”„ Last Modified: April 8, 2026, 5:34 p.m.

6.4

CVSS3.1

CVE-2024-9115 - Common Tools for Site <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File U…

The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and a…

πŸ“… Published: Sept. 26, 2024, 9:29 a.m. πŸ”„ Last Modified: April 8, 2026, 5:24 p.m.
Total resulsts: 349182
Page 8466 of 34,919
Β« previous page Β» next page
Filters