4.8

CVSS3.1

CVE-2024-7084 - Ajax Search Lite < 4.12.1 - Admin+ Stored XSS

The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.

πŸ“… Published: Aug. 6, 2024, 6 a.m. πŸ”„ Last Modified: May 28, 2025, 7:41 p.m.

6.1

CVSS3.1

CVE-2024-7082 - easy-table-of-contents < 2.0.68 - Editor+ Stored XSS

The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.

πŸ“… Published: Aug. 6, 2024, 6 a.m. πŸ”„ Last Modified: May 28, 2025, 7:43 p.m.

5.4

CVSS3.1

CVE-2024-6766 - Shortcodes Ultimate Pro < 7.2.1 - Contributor+ Stored XSS

The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

πŸ“… Published: Aug. 6, 2024, 6 a.m. πŸ”„ Last Modified: June 13, 2025, 12:16 a.m.

6.1

CVSS3.1

CVE-2024-6651 - WordPress File Upload < 4.24.8 - Reflected XSS

The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Aug. 6, 2024, 6 a.m. πŸ”„ Last Modified: April 11, 2025, 3:13 p.m.

5.3

CVSS3.1

CVE-2024-6201 - HaloITSM - Emailing Template Injection

HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

πŸ“… Published: Aug. 6, 2024, 5:59 a.m. πŸ”„ Last Modified: March 25, 2025, 4:42 p.m.

8

CVSS3.1

CVE-2024-6200 - HaloITSM - Stored Cross-Site Scripting in Tickets

HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user accessing a ticket. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

πŸ“… Published: Aug. 6, 2024, 5:54 a.m. πŸ”„ Last Modified: Aug. 29, 2024, 5:53 p.m.

8.8

CVSS3.1

CVE-2024-5709 - WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion

The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and with post permissions granted by an Administ…

πŸ“… Published: Aug. 6, 2024, 5:31 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

6.4

CVSS3.1

CVE-2024-5708 - WPBakery <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting

The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜link’ parameter in all versions up to, and including, 7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access …

πŸ“… Published: Aug. 6, 2024, 5:31 a.m. πŸ”„ Last Modified: April 8, 2026, 4:42 p.m.

6.5

CVSS3.1

CVE-2024-39817 -

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.

πŸ“… Published: Aug. 6, 2024, 4:54 a.m. πŸ”„ Last Modified: March 18, 2025, 9:15 p.m.

5.3

CVSS4.0

CVE-2024-7506 - itsourcecode Tailoring Management System setlogo.php unrestricted upload

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /setlogo.php. The manipulation of the argument bgimg leads to unrestricted upload. The attack can be launched remotely. T…

πŸ“… Published: Aug. 6, 2024, 4:31 a.m. πŸ”„ Last Modified: Sept. 11, 2024, 8:02 p.m.
Total resulsts: 349182
Page 8944 of 34,919
Β« previous page Β» next page
Filters