5.4

CVSS3.1

CVE-2024-26055 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue typically requires us…

📅 Published: June 13, 2024, 7:52 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:01 a.m.

5.4

CVSS3.1

CVE-2024-36161 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…

📅 Published: June 13, 2024, 7:52 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:21 a.m.

5.4

CVSS3.1

CVE-2024-36199 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…

📅 Published: June 13, 2024, 7:52 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:21 a.m.

5.4

CVSS3.1

CVE-2024-36232 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…

📅 Published: June 13, 2024, 7:52 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:21 a.m.

6.4

CVSS3.1

CVE-2024-4615 - Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Hea…

The Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Builder. One Click Import: No Coding Required! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Horizontal Nav Menu' widget in all versions up to, and includin…

📅 Published: June 13, 2024, 7:31 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-5265 - WPBakery Page Builder <= 7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via VC Sing…

The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it …

📅 Published: June 13, 2024, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

5.3

CVSS3.1

CVE-2024-4576 - TIBCO EBX File Inclusion Vulnerability

The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration and potentially sensitive information.

📅 Published: June 13, 2024, 6:31 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:43 a.m.

6.1

CVSS3.1

CVE-2024-4149 - Floating Chat Widget < 3.2.3 - Admin+ Stored XSS

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attack…

📅 Published: June 13, 2024, 6 a.m. 🔄 Last Modified: March 26, 2025, 3:15 p.m.

7.2

CVSS3.1

CVE-2024-4145 - Search & Replace < 3.2.2 - Admin+ SQL injection

The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).

📅 Published: June 13, 2024, 6 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:42 a.m.

9.8

CVSS3.1

CVE-2024-3552 - Web Directory Free < 1.7.0 - Unauthenticated SQL Injection

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.

📅 Published: June 13, 2024, 6 a.m. 🔄 Last Modified: March 25, 2025, 2:15 p.m.
Total resulsts: 349182
Page 9475 of 34,919
« previous page » next page
Filters