4.7

CVSS3.1

CVE-2024-5678 - SQL Injection

Zohocorp ManageEngine Applications Manager versionsΒ 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.

πŸ“… Published: Aug. 1, 2024, 6:54 a.m. πŸ”„ Last Modified: Aug. 15, 2024, 6:05 p.m.

4.3

CVSS3.1

CVE-2024-5331 - Breakdance <= 1.7.2 - Missing Authorization

The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.

πŸ“… Published: Aug. 1, 2024, 6:47 a.m. πŸ”„ Last Modified: April 8, 2026, 5:27 p.m.

6.4

CVSS3.1

CVE-2024-5330 - Breakdance <= 1.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contrib…

πŸ“… Published: Aug. 1, 2024, 6:47 a.m. πŸ”„ Last Modified: April 8, 2026, 5:11 p.m.

6.4

CVSS3.1

CVE-2024-7302 - Blog2Social: Social Media Auto Post & Scheduler <= 7.5.4 - Authenticated (Author+) Stored Cross-Sit…

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit…

πŸ“… Published: Aug. 1, 2024, 6:47 a.m. πŸ”„ Last Modified: April 8, 2026, 5:09 p.m.

7.1

CVSS3.1

CVE-2024-6529 - Ultimate Classified Listings < 1.4 - Reflected XSS

The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Aug. 1, 2024, 6 a.m. πŸ”„ Last Modified: April 10, 2025, 1:49 p.m.

6.5

CVSS3.1

CVE-2024-6496 - Light Poll <= 1.0.0 - Polls Deletion via CSRF

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perform such action via a CSRF attack

πŸ“… Published: Aug. 1, 2024, 6 a.m. πŸ”„ Last Modified: June 9, 2025, 9:29 p.m.

4.8

CVSS3.1

CVE-2024-4090 - My Sticky Bar < 2.7.2 - Admin+ Stored XSS

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_h…

πŸ“… Published: Aug. 1, 2024, 6 a.m. πŸ”„ Last Modified: June 10, 2025, 4:12 p.m.

8.1

CVSS3.1

CVE-2024-3983 - WooCommerce Customers Manager < 30.1 - Bulk Action via CSRF

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks

πŸ“… Published: Aug. 1, 2024, 6 a.m. πŸ”„ Last Modified: May 29, 2025, 5:22 p.m.

4.8

CVSS3.1

CVE-2024-2872 - Swift Framework < 2024.04.30 - Contributor+ Stored XSS

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

πŸ“… Published: Aug. 1, 2024, 6 a.m. πŸ”„ Last Modified: July 16, 2025, 3:49 p.m.

6.5

CVSS3.1

CVE-2024-2843 - WooCommerce Customers Manager < 30.1 - User Deletion via CSRF

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks

πŸ“… Published: Aug. 1, 2024, 6 a.m. πŸ”„ Last Modified: May 29, 2025, 5:23 p.m.
Total resulsts: 349182
Page 8980 of 34,919
Β« previous page Β» next page
Filters