Latest CVE Feed
-
5.4
MEDIUMCVE-2024-6392
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for au... Read more
Affected Products : sirv- Published: Jul. 11, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-6136
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks... Read more
Affected Products : wp_estore- Published: Aug. 12, 2024
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2024-6282
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element in all versions up to, and including 2.0.6.4 due to ins... Read more
Affected Products : master_addons- Published: Sep. 10, 2024
- Modified: Sep. 26, 2024
-
5.4
MEDIUMCVE-2024-5941
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1. This make... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-5648
The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, wit... Read more
Affected Products :- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-5595
The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored C... Read more
Affected Products : essential_blocks- Published: Aug. 02, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2024-5383
A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation of the argument file leads to cross site scripting. It is possible to initiate the ... Read more
Affected Products : easyadmin- Published: May. 26, 2024
- Modified: Aug. 21, 2025
-
5.4
MEDIUMCVE-2024-5417
The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Sit... Read more
Affected Products : gutentor- Published: Aug. 29, 2024
- Modified: Oct. 07, 2024
-
5.4
MEDIUMCVE-2024-57240
A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file.... Read more
Affected Products : webviewer- Published: Mar. 03, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-57189
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.... Read more
Affected Products : erxes- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2024-57329
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.... Read more
Affected Products : hortusfox- Published: Jan. 23, 2025
- Modified: Aug. 14, 2025
-
5.4
MEDIUMCVE-2024-56923
Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious paylo... Read more
Affected Products : silverpeas- Published: Jan. 22, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-56830
The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl's builtin rand() if no strong randomization module is present.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Cryptography
-
5.4
MEDIUMCVE-2024-56939
LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.... Read more
Affected Products : learndash- Published: Feb. 12, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-56512
Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include bindin... Read more
Affected Products : nifi- Published: Dec. 28, 2024
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2024-56471
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attac... Read more
Affected Products : aspera_shares- Published: Feb. 05, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
5.4
MEDIUMCVE-2024-56341
IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent... Read more
- Published: Apr. 02, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-56312
A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field of a Project Dashboard. When a user clicks on the project Dashboard name, t... Read more
Affected Products : redcap- Published: Dec. 22, 2024
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2024-56253
Missing Authorization vulnerability in supsystic.com Data Tables Generator by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.36.... Read more
Affected Products : data_tables_generator- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-56222
Cross-Site Request Forgery (CSRF) vulnerability in Codebard CodeBard Help Desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a through 1.1.1.... Read more
Affected Products : codebard_help_desk- Published: Dec. 31, 2024
- Modified: Mar. 19, 2025