8.8

CVSS3.1

CVE-2024-3564 - Content Blocks (Custom Post Widget) <= 3.3.0 - Authenticated (Contributor+) Local File Inclusion vi…

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the plugin's 'content_block' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and exec…

πŸ“… Published: June 1, 2024, 3:31 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-3565 - Content Blocks (Custom Post Widget) <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss…

πŸ“… Published: June 1, 2024, 3:31 a.m. πŸ”„ Last Modified: April 8, 2026, 4:37 p.m.

6.4

CVSS3.1

CVE-2024-4711 - WordPress Infinite Scroll – Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scrip…

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

πŸ“… Published: June 1, 2024, 2:32 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-2933 - Page Builder Gutenberg Blocks – CoBlocks <= 3.1.9 - Authenticated (Contributor+) Stored Cross-Site …

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Social Profiles widget in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo…

πŸ“… Published: June 1, 2024, 1:54 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-38428 - wget: Misinterpretation of input may lead to improper behavior

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

πŸ“… Published: June 1, 2024, midnight πŸ”„ Last Modified: April 21, 2025, 10:15 a.m.

8.1

CVSS3.1

CVE-2024-5138 -

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of t…

πŸ“… Published: May 31, 2024, 9:02 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:21 p.m.

7.5

CVSS3.1

CVE-2024-34009 - moodle: ReCAPTCHA can be bypassed on the login page

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.

πŸ“… Published: May 31, 2024, 8:49 p.m. πŸ”„ Last Modified: May 30, 2025, 4:48 p.m.

3.5

CVSS3.1

CVE-2024-34008 - moodle: CSRF risk in analytics management of models

Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

πŸ“… Published: May 31, 2024, 8:44 p.m. πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

8.8

CVSS3.1

CVE-2024-34007 - moodle: logout CSRF in admin/tool/mfa/auth.php

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

πŸ“… Published: May 31, 2024, 8:40 p.m. πŸ”„ Last Modified: May 30, 2025, 4:48 p.m.

4.3

CVSS3.1

CVE-2024-34006 - moodle: unsanitized HTML in site log for config_log_created

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

πŸ“… Published: May 31, 2024, 8:36 p.m. πŸ”„ Last Modified: May 30, 2025, 4:48 p.m.
Total resulsts: 349182
Page 9614 of 34,919
Β« previous page Β» next page
Filters