7.5

CVSS3.1

CVE-2024-3756 - MF Gig Calendar <= 1.2.1 - Arbitrary Event Deletion via CSRF

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack

📅 Published: May 6, 2024, 6 a.m. 🔄 Last Modified: April 18, 2025, 12:54 p.m.

5.4

CVSS3.1

CVE-2024-3755 - MF Gig Calendar <= 1.2.1 - Editor+ Stored XSS

The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

📅 Published: May 6, 2024, 6 a.m. 🔄 Last Modified: April 18, 2025, 12:55 p.m.

5.4

CVSS3.1

CVE-2024-3752 - Crelly Slider <= 1.4.5 - Admin+ Stored XSS

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

📅 Published: May 6, 2024, 6 a.m. 🔄 Last Modified: May 8, 2025, 4:41 p.m.

5.9

CVSS3.1

CVE-2024-0904 - Fancy Product Designer < 6.1.81 - Admin+ Cross Site Scripting

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

📅 Published: May 6, 2024, 6 a.m. 🔄 Last Modified: May 8, 2025, 4:28 p.m.

3.5

CVSS3.1

CVE-2024-4525 - Campcodes Complete Web-Based School Management System student_payment_details4.php cross site scrip…

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /view/student_payment_details4.php. The manipulation of the argument index leads to cross site scripting. The attack can be …

📅 Published: May 6, 2024, 5:31 a.m. 🔄 Last Modified: Feb. 19, 2025, 6:02 p.m.

3.5

CVSS3.1

CVE-2024-4524 - Campcodes Complete Web-Based School Management System student_payment_invoice.php cross site script…

A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/student_payment_invoice.php. The manipulation of the argument desc leads to cross site scripting. It is possible to initiate t…

📅 Published: May 6, 2024, 5:31 a.m. 🔄 Last Modified: Feb. 19, 2025, 6:02 p.m.

3.5

CVSS3.1

CVE-2024-4523 - Campcodes Complete Web-Based School Management System teacher_attendance_history1.php cross site sc…

A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /view/teacher_attendance_history1.php. The manipulation of the argument year leads to cross site script…

📅 Published: May 6, 2024, 5 a.m. 🔄 Last Modified: Feb. 19, 2025, 6:02 p.m.

3.5

CVSS3.1

CVE-2024-4522 - Campcodes Complete Web-Based School Management System teacher_salary_details.php cross site scripti…

A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/teacher_salary_details.php. The manipulation of the argument index leads to cross site scripting. The attack…

📅 Published: May 6, 2024, 4:31 a.m. 🔄 Last Modified: Feb. 19, 2025, 6:01 p.m.

3.5

CVSS3.1

CVE-2024-4521 - Campcodes Complete Web-Based School Management System teacher_salary_details2.php cross site script…

A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teacher_salary_details2.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the at…

📅 Published: May 6, 2024, 4:31 a.m. 🔄 Last Modified: Feb. 19, 2025, 6:01 p.m.

3.5

CVSS3.1

CVE-2024-4519 - Campcodes Complete Web-Based School Management System teacher_salary_details3.php cross site script…

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/teacher_salary_details3.php. The manipulation of the argument month leads to cross site scripting. The attack may be…

📅 Published: May 6, 2024, 4 a.m. 🔄 Last Modified: Feb. 19, 2025, 6 p.m.
Total resulsts: 349182
Page 9974 of 34,919
« previous page » next page
Filters