6.4

CVSS3.1

CVE-2024-9117 - Mapplic Lite <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inโ€ฆ

๐Ÿ“… Published: Sept. 26, 2024, 9:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:12 p.m.

6.4

CVSS3.1

CVE-2024-9173 - GF Custom Style <= 2.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, toโ€ฆ

๐Ÿ“… Published: Sept. 26, 2024, 9:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:04 p.m.

6.4

CVSS3.1

CVE-2024-9127 - Super Testimonials <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via alignmenโ€ฆ

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜alignmentโ€™ parameter in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level aโ€ฆ

๐Ÿ“… Published: Sept. 26, 2024, 9:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:53 p.m.

6.4

CVSS3.1

CVE-2024-9125 - king_IE <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject โ€ฆ

๐Ÿ“… Published: Sept. 26, 2024, 9:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:50 p.m.

4.3

CVSS3.1

CVE-2024-47337 - WordPress Joy Of Text Lite plugin <= 2.3.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: from n/a through <= 2.3.1.

๐Ÿ“… Published: Sept. 26, 2024, 8:49 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:19 p.m.

5.3

CVSS3.1

CVE-2024-47044 -

Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Seโ€ฆ

๐Ÿ“… Published: Sept. 26, 2024, 8:34 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-9025 - Sight โ€“ Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Infoโ€ฆ

The Sight โ€“ Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to expose pโ€ฆ

๐Ÿ“… Published: Sept. 26, 2024, 8:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:33 p.m.

6.1

CVSS3.1

CVE-2024-8872 - Store Hours for WooCommerce <= 4.3.20 - Reflected Cross-Site Scripting

The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.3.20. This makes it possible for unauthenticated attackers to inject arbitrary web scrโ€ฆ

๐Ÿ“… Published: Sept. 26, 2024, 8:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:59 p.m.

3.1

CVSS3.1

CVE-2024-47003 - DoS via non-string message using permalink embed

Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string,ย which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend.

๐Ÿ“… Published: Sept. 26, 2024, 8:05 a.m. ๐Ÿ”„ Last Modified: Sept. 26, 2024, 6:42 p.m.

5.4

CVSS3.1

CVE-2024-42406 - Unauthorized access on archived channels

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allowsย an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as wโ€ฆ

๐Ÿ“… Published: Sept. 26, 2024, 8:04 a.m. ๐Ÿ”„ Last Modified: Oct. 1, 2024, 11:15 a.m.
Total resulsts: 349182
Page 8467 of 34,919
ยซ previous page ยป next page
Filters