Latest CVE Feed
-
4.3
MEDIUMCVE-2024-3243
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticate... Read more
Affected Products : customer_reviews_for_woocommerce- Published: Apr. 16, 2024
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2024-54357
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.10.... Read more
Affected Products : avada- Published: Dec. 16, 2024
- Modified: Apr. 14, 2025
-
4.3
MEDIUMCVE-2024-1158
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buddyforms_new_page fun... Read more
Affected Products : buddyforms- Published: Mar. 13, 2024
- Modified: Mar. 11, 2025
-
4.3
MEDIUMCVE-2008-6945
Multiple cross-site scripting (XSS) vulnerabilities in Interchange 5.7 before 5.7.1, 5.6 before 5.6.1, and 5.4 before 5.4.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mv_order_item CGI variable parameter in Core, (2) the cou... Read more
Affected Products : interchange- Published: Aug. 12, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-8030
Cross-site scripting (XSS) vulnerability in sendPwMail.do in Cisco WebEx Meetings Server allows remote attackers to inject arbitrary web script or HTML via the email parameter, aka Bug ID CSCuj40381.... Read more
Affected Products : webex_meetings_server- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-2033
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber a... Read more
Affected Products : video_conferencing_with_zoom- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-27339
Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength allows Cross Site Request Forgery. This issue affects Minimum Password Strength: from n/a through 1.2.0.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-33670
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictio... Read more
Affected Products : passbolt_api- Published: Apr. 26, 2024
- Modified: Jun. 18, 2025
-
4.3
MEDIUMCVE-2018-3759
private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a publ... Read more
Affected Products : private_address_check- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3021
Cross-site scripting (XSS) vulnerability in Site Calendar 'mycaljp' plugin 2.0.0 through 2.0.6, as used in the Japanese extended package of Geeklog 1.5.0 through 1.5.2 and when distributed 20090629 or earlier, allows remote attackers to inject arbitrary w... Read more
- Published: Aug. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-5639
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it ... Read more
Affected Products : user_profile_picture- Published: Jun. 21, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3410
The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : footer_contacts_bar- Published: Jul. 09, 2024
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2024-4086
The CM Tooltip Glossary – Powerful Glossary Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.11. This is due to missing or incorrect nonce validation when saving settings. This makes it poss... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5132
Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.... Read more
Affected Products : projectdox- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-37095
Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envira Photo Gallery: from n/a through 1.8.7.3.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2014-8012
Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.... Read more
Affected Products : adaptive_security_appliance_software- Published: Dec. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-3301
Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.... Read more
Affected Products : rdiffweb- Published: Sep. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34807
Cross-Site Request Forgery (CSRF) vulnerability in CodeBard Fast Custom Social Share by CodeBard.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.2.... Read more
Affected Products : fast_custom_social_share- Published: May. 17, 2024
- Modified: Mar. 11, 2025
-
4.3
MEDIUMCVE-2024-0797
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and inc... Read more
Affected Products : woot- Published: Feb. 05, 2024
- Modified: May. 15, 2025
-
4.3
MEDIUMCVE-2011-2675
Cross-site scripting (XSS) vulnerability in Enkai-kun before 110916 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : enkai- Published: Oct. 10, 2011
- Modified: Apr. 11, 2025