4.9

CVSS3.1

CVE-2024-31397 -

Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative privilege may be able to cause a denial-of-service (DoS) condition.

πŸ“… Published: June 11, 2024, 5:34 a.m. πŸ”„ Last Modified: Feb. 13, 2026, 3:30 p.m.

5.3

CVSS3.1

CVE-2024-31399 -

Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.

πŸ“… Published: June 11, 2024, 5:34 a.m. πŸ”„ Last Modified: March 20, 2025, 7:15 p.m.

5.3

CVSS3.1

CVE-2024-3723 - Advanced Contact form 7 DB <= 2.0.2 - Sensitive Information Exposure

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this …

πŸ“… Published: June 11, 2024, 5:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-4319 - Advanced Contact form 7 DB <= 2.0.2 - Missing Authorization to Unauthenticated Information Disclosu…

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download the entry data for s…

πŸ“… Published: June 11, 2024, 5:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-31402 -

Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.

πŸ“… Published: June 11, 2024, 5:21 a.m. πŸ”„ Last Modified: March 28, 2025, 9:15 p.m.

4.3

CVSS3.1

CVE-2024-31398 -

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.

πŸ“… Published: June 11, 2024, 5:20 a.m. πŸ”„ Last Modified: March 13, 2025, 2:15 p.m.

6.4

CVSS3.1

CVE-2024-5530 - ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (forme…

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WL: Product Horizontal Filter widget in all versions up to, and including, 2.9.0 due to insufficie…

πŸ“… Published: June 11, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

4.3

CVSS3.1

CVE-2024-31404 -

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.

πŸ“… Published: June 11, 2024, 4:27 a.m. πŸ”„ Last Modified: May 28, 2025, 8:09 p.m.

5.4

CVSS3.1

CVE-2024-31403 -

Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.

πŸ“… Published: June 11, 2024, 4:27 a.m. πŸ”„ Last Modified: May 28, 2025, 8:09 p.m.

9

CVSS3.1

CVE-2024-31401 -

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.

πŸ“… Published: June 11, 2024, 4:26 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 3:30 p.m.
Total resulsts: 349182
Page 9509 of 34,919
Β« previous page Β» next page
Filters