7.1

CVSS3.1

CVE-2024-1940 - Brizy – Page Builder <= 2.4.41 - Authenticated(Contributor+) Stored Cross-Site Scripting

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4.41 due to insufficient input sanitization performed only on the client side and insufficient output escaping. This makes it possible for authenticate…

πŸ“… Published: June 5, 2024, 5:33 a.m. πŸ”„ Last Modified: April 8, 2026, 7:20 p.m.

7.2

CVSS3.1

CVE-2024-2087 - Brizy – Page Builder <= 2.4.43 - Unauthenticated Stored Cross-Site Scripting via Form

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s…

πŸ“… Published: June 5, 2024, 5:33 a.m. πŸ”„ Last Modified: April 8, 2026, 6:20 p.m.

9.8

CVSS3.1

CVE-2024-4295 - Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the β€˜hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

πŸ“… Published: June 5, 2024, 5:33 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-1161 - Brizy – Page Builder <= 2.4.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custo…

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with c…

πŸ“… Published: June 5, 2024, 5:33 a.m. πŸ”„ Last Modified: April 8, 2026, 4:43 p.m.

6.5

CVSS3.1

CVE-2024-5149 - BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness

The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.

πŸ“… Published: June 5, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

9.3

CVSS4.0

CVE-2024-5262 - ProjectDiscovery Interactsh - Files or Directories Accessible to External Parties

Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and subdirectories of where the victim runs interactsh-server via anonymous login.

πŸ“… Published: June 5, 2024, 4 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

5.3

CVSS3.1

CVE-2024-5483 - LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of get_items_permissions_check function. This makes it possible for unauthenticated attackers to extract basic inf…

πŸ“… Published: June 5, 2024, 2:34 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

6.4

CVSS3.1

CVE-2024-5317 - Newsletter <= 8.3.4 - Unauthenticated Stored Cross-Site Scripting via np1

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa…

πŸ“… Published: June 5, 2024, 1:56 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

5.3

CVSS4.0

CVE-2024-5636 - itsourcecode Bakery Online Ordering System index.php sql injection

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file report/index.php. The manipulation of the argument procduct leads to sql injection. The attack may be launched remotely. The e…

πŸ“… Published: June 5, 2024, 12:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

7.5

CVSS3.1

CVE-2024-4084 - SSRF vulnerability in mintplex-labs/anything-llm

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the official fix intended to restrict access to intranet IP addresses and protocols. Despite efforts to filter out intranet IP addresses starting with 192, 172…

πŸ“… Published: June 5, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:42 a.m.
Total resulsts: 349182
Page 9579 of 34,919
Β« previous page Β» next page
Filters