6.4

CVSS3.1

CVE-2024-4313 - Table Addons for Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The Table Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

📅 Published: June 22, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

7.2

CVSS3.1

CVE-2024-5791 - Appointment Booking and Online Scheduling <= 4.4.2 - Missing Authorization to Unauthenticated Store…

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to, and including, 4.4.2 due to missing authorization checks on processAction function, as well as insufficient input saniti…

📅 Published: June 22, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

6.4

CVSS3.1

CVE-2024-2484 - Orbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Se…

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versions up to, and including, 2.10.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

📅 Published: June 22, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

6.4

CVSS3.1

CVE-2024-5346 - Flatsome | Multi-Purpose Responsive WooCommerce Theme <= 3.18.7 - Authenticated (Contributor+) Stor…

The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the UX Countdown, Video Button, UX Video, UX Slider, UX Sidebar, and UX Payment Icons shortcodes in all versions up to, and including, 3.18.7 due to insufficient input sanitization and output escaping on user supplied…

📅 Published: June 22, 2024, 2:01 a.m. 🔄 Last Modified: April 8, 2026, 4:36 p.m.

6.5

CVSS3.1

CVE-2024-6120 - Sparkle Demo Importer <= 1.4.7 - Missing Authorization to Authorized(Subscriber+) Post/Pages/Attach…

The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access an…

📅 Published: June 21, 2024, 11:33 p.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

9.3

CVSS3.1

CVE-2020-27352 -

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading syst…

📅 Published: June 21, 2024, 8:06 p.m. 🔄 Last Modified: Aug. 26, 2025, 5:20 p.m.

8.2

CVSS3.1

CVE-2023-37898 - Safe mode Cross-site Scripting (XSS) vulnerability in Joplin

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted note opened in safe mode to execute arbitrary code. `packages/renderer/MarkupToHtml.ts` renders note content in safe mode by surrounding it with <pre> and </pre>, without …

📅 Published: June 21, 2024, 7:45 p.m. 🔄 Last Modified: April 11, 2025, 5:19 p.m.

8.2

CVSS3.1

CVE-2023-38506 - Cross-site Scripting (XSS) when pasting HTML into the rich text editor in Joplin

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasting untrusted data into the rich text editor to execute arbitrary code. HTML pasted into the rich text editor is not sanitized (or not sanitized properly). As such, the `onload` at…

📅 Published: June 21, 2024, 7:43 p.m. 🔄 Last Modified: April 11, 2025, 3:17 p.m.

8.2

CVSS3.1

CVE-2023-39517 - Cross site scripting (XSS) when clicking on an untrusted `<map>` link in Joplin

Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML sanitizer (`packages/renderer/htmlUtils.ts::sanitizeHtml`) preserves `<map>` `<ar…

📅 Published: June 21, 2024, 7:41 p.m. 🔄 Last Modified: Nov. 21, 2024, 8:15 a.m.

8.9

CVSS3.1

CVE-2023-45673 - Arbitrary code execution on click of PDF links in Joplin

Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link in a PDF in an untrusted note to execute arbitrary shell commands. Clicking links in PDFs allows for arbitrary code execution because Joplin de…

📅 Published: June 21, 2024, 7:38 p.m. 🔄 Last Modified: April 11, 2025, 3:17 p.m.
Total resulsts: 349182
Page 9358 of 34,919
« previous page » next page
Filters