6.4

CVSS3.1

CVE-2024-1814 - Spectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scr…

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f…

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: April 8, 2026, 7:20 p.m.

6.4

CVSS3.1

CVE-2024-3997 - Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14…

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pagepiling widget in all versions up to, and including, 3.14.1 due to insufficient input sanitization and output escapin…

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-4575 - LayerSlider 7.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via ls_search_form Sh…

The LayerSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ls_search_form shortcode in version 7.11.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-…

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: July 13, 2025, 9:07 p.m.

6.4

CVSS3.1

CVE-2024-1815 - Spectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scr…

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: April 8, 2026, 4:40 p.m.

4.3

CVSS3.1

CVE-2023-6502 - Inefficient Regular Expression Complexity in GitLab

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. It is possible for an attacker to cause a denial of service using a crafted wiki page.

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: Dec. 16, 2024, 3:02 p.m.

5.4

CVSS3.1

CVE-2023-7045 - Cross-Site Request Forgery (CSRF) in GitLab

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: Dec. 16, 2024, 2:53 p.m.

4.3

CVSS3.1

CVE-2024-1947 - Improper Handling of Highly Compressed Data (Data Amplification) in GitLab

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls.

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:14 p.m.

4.4

CVSS3.1

CVE-2024-5258 - Authorization Bypass Through User-Controlled Key in GitLab

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:09 p.m.

6.5

CVSS3.1

CVE-2024-5165 - Eclipse Ditto User Interface vulnerable to XSS due to Improper Neutralization of Input

In Eclipse Ditto versions 3.0.0 to 3.5.5, the user input of several input fields of the Eclipse Ditto Explorer User Interface https://eclipse.dev/ditto/user-interface.html was not properly neutralized and thus vulnerable to both Reflected and Stored XSS (Cross Site Scripting). Several inputs…

πŸ“… Published: May 23, 2024, 9:56 a.m. πŸ”„ Last Modified: Jan. 31, 2025, 2:46 p.m.

8.8

CVSS3.1

CVE-2024-4779 - Unlimited Elements for Elementor <= 1.5.107 - Authenticated (Contributor+) SQL Injection via data[p…

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the β€˜data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati…

πŸ“… Published: May 23, 2024, 9:32 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.
Total resulsts: 344032
Page 9176 of 34,404
Β« previous page Β» next page
Filters