6.4

CVSS3.1

CVE-2024-4485 - The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <…

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_custom_attributes’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and out…

📅 Published: May 24, 2024, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

4.3

CVSS3.1

CVE-2024-0893 - Schema App Structured Data <= 2.2.0 - Missing Authorization

The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber access or higher, to…

📅 Published: May 24, 2024, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.

5.1

CVSS4.0

CVE-2023-1111 - FastCMS New Article Tab cross site scripting

A vulnerability was found in FastCMS up to 0.1.5 and classified as problematic. Affected by this issue is some unknown functionality of the component New Article Tab. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The exploit has been disc…

📅 Published: May 24, 2024, 6:31 a.m. 🔄 Last Modified: Nov. 21, 2024, 7:38 a.m.

6.8

CVSS3.1

CVE-2024-36361 -

Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typicall…

📅 Published: May 24, 2024, 6:04 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2023-1001 - xuliangzhan vxe-table vxe-textarea textarea.js export cross site scripting

A vulnerability, which was classified as problematic, has been found in xuliangzhan vxe-table up to 3.7.9. This issue affects the function export of the file packages/textarea/src/textarea.js of the component vxe-textarea. The manipulation of the argument inputValue leads to cross site scripting. T…

📅 Published: May 24, 2024, 6 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2024-5142 - XSS in Hubshare's social module

Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser

📅 Published: May 24, 2024, 5:58 a.m. 🔄 Last Modified: Feb. 23, 2026, 11:16 a.m.

8.1

CVSS3.1

CVE-2024-0867 - Email Log <= 2.4.8 - Unauthenticated Hook Injection

The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the at…

📅 Published: May 24, 2024, 5:30 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-1134 - SEOPress – On-site SEO <= 7.5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as others in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers,…

📅 Published: May 24, 2024, 5:30 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

6.4

CVSS3.1

CVE-2024-3718 - The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: May 24, 2024, 5:30 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

6.4

CVSS3.1

CVE-2024-3557 - WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scr…

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo…

📅 Published: May 24, 2024, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.
Total resulsts: 349182
Page 9676 of 34,919
« previous page » next page
Filters