6.9

CVSS4.0

CVE-2025-0206 - code-projects Online Shoe Store index.php access control

A vulnerability classified as critical was found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed t…

📅 Published: Jan. 4, 2025, noon 🔄 Last Modified: Jan. 22, 2025, 3:24 p.m.

6.5

CVSS3.1

CVE-2024-12195 - WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt cha…

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 du…

📅 Published: Jan. 4, 2025, 11:24 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.

6.1

CVSS3.1

CVE-2024-12279 - WP Social AutoConnect <= 4.6.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forg…

📅 Published: Jan. 4, 2025, 11:16 a.m. 🔄 Last Modified: April 8, 2026, 4:46 p.m.

6.4

CVSS3.1

CVE-2024-12475 - WP Multi Store Locator <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…

📅 Published: Jan. 4, 2025, 11:16 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.

6.1

CVSS3.1

CVE-2024-12221 - Turnkey bbPress by WeaverTheme <= 1.6.3 - Reflected Cross-Site Scripting via _wpnonce Parameter

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

📅 Published: Jan. 4, 2025, 9:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-0205 - code-projects Online Shoe Store details2.php sql injection

A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /details2.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the pu…

📅 Published: Jan. 4, 2025, 9 a.m. 🔄 Last Modified: Jan. 22, 2025, 3:33 p.m.

6.4

CVSS3.1

CVE-2024-11930 - Taskbuilder – WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) St…

The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppm_tasks shortcode in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. Th…

📅 Published: Jan. 4, 2025, 8:22 a.m. 🔄 Last Modified: April 8, 2026, 5:35 p.m.

9.9

CVSS3.1

CVE-2024-12583 - Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitra…

The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possi…

📅 Published: Jan. 4, 2025, 8:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-0204 - code-projects Online Shoe Store details.php sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to t…

📅 Published: Jan. 4, 2025, 7:31 a.m. 🔄 Last Modified: Jan. 22, 2025, 3:42 p.m.

8.8

CVSS3.1

CVE-2024-10932 - Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'

The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additi…

📅 Published: Jan. 4, 2025, 7:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345149
Page 6882 of 34,515
« previous page » next page
Filters