6.5

CVSS3.1

CVE-2024-35151 - IBM OpenPages information disclosure

IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.

๐Ÿ“… Published: Aug. 22, 2024, 10:12 a.m. ๐Ÿ”„ Last Modified: Aug. 23, 2024, 3:32 p.m.

6.4

CVSS3.1

CVE-2024-6870 - Responsive Lightbox & Gallery <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via Fiโ€ฆ

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping affecting the rl_upload_image AJAX endpoint. This makes it possible for authentโ€ฆ

๐Ÿ“… Published: Aug. 22, 2024, 9:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:29 p.m.

6.4

CVSS3.1

CVE-2024-7778 - Orbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Filโ€ฆ

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.10.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access anโ€ฆ

๐Ÿ“… Published: Aug. 22, 2024, 9:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:19 p.m.

5.3

CVSS3.1

CVE-2024-8072 - Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbiโ€ฆ

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

๐Ÿ“… Published: Aug. 22, 2024, 7:52 a.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 8:08 p.m.

4.7

CVSS3.1

CVE-2024-8071 - System Role with edit access to permissions can elevate themselves to system admin

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the `manage_โ€ฆ

๐Ÿ“… Published: Aug. 22, 2024, 6:39 a.m. ๐Ÿ”„ Last Modified: Aug. 23, 2024, 3:34 p.m.

5.3

CVSS3.1

CVE-2024-42411 - User creation date manipulation in POST /api/v4/users

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allowsย a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

๐Ÿ“… Published: Aug. 22, 2024, 6:32 a.m. ๐Ÿ”„ Last Modified: Aug. 23, 2024, 4:04 p.m.

4.6

CVSS3.1

CVE-2024-40886 - One-click Client-Side Path Traversal Leading to CSRF in User Management admin page

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows forย a one-click client-side path traversal that is leading to CSRF in User Management page of the system console.

๐Ÿ“… Published: Aug. 22, 2024, 6:32 a.m. ๐Ÿ”„ Last Modified: Aug. 23, 2024, 4:09 p.m.

4.3

CVSS3.1

CVE-2024-43813 - IDOR when marking read a user's channel

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allowsย any authenticated user, including guests, to mark any channel inside any team as read for any user.

๐Ÿ“… Published: Aug. 22, 2024, 6:30 a.m. ๐Ÿ”„ Last Modified: Aug. 23, 2024, 3:35 p.m.

4.9

CVSS3.1

CVE-2024-39810 - Server crash via Elasticsearch certificate file

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the conneโ€ฆ

๐Ÿ“… Published: Aug. 22, 2024, 6:30 a.m. ๐Ÿ”„ Last Modified: Aug. 23, 2024, 4:16 p.m.

4.3

CVSS3.1

CVE-2024-32939 - Email addresses of remote users visible in props regardless of server settings

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."

๐Ÿ“… Published: Aug. 22, 2024, 6:29 a.m. ๐Ÿ”„ Last Modified: Aug. 23, 2024, 4:17 p.m.
Total resulsts: 349182
Page 8758 of 34,919
ยซ previous page ยป next page
Filters