Latest CVE Feed
-
4.3
MEDIUMCVE-2023-1339
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-42339
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products : identity- Published: Aug. 25, 2024
- Modified: Aug. 30, 2024
-
4.3
MEDIUMCVE-2019-4512
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.... Read more
- Published: Oct. 09, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-5856
The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action in all versions up to, and including, 2.2.1. This makes it possible for authenticated attacke... Read more
Affected Products :- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-3126
The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'b2bkingdownloadpricelist' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with su... Read more
Affected Products : b2bking- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6070
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where... Read more
Affected Products : enterprise_security_manager- Published: Nov. 29, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-5936
The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated a... Read more
Affected Products : vr_calendar- Published: Jun. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2012-1070
Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the "return url parame... Read more
- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-48714
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFie... Read more
Affected Products : framework- Published: Jan. 23, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4233
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.... Read more
- Published: May. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30546
Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-27846
Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create or modify slider.... Read more
Affected Products : yoo_slider- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-1414
Cross-site scripting (XSS) vulnerability in the tibbr web server, as used in TIBCO tibbr 1.0.0 through 1.5.0 and tibbr Service 1.0.0 through 1.5.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-43337
Cross-Site Request Forgery (CSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.7.0.... Read more
Affected Products : brave- Published: Aug. 26, 2024
- Modified: Aug. 27, 2024
-
4.3
MEDIUMCVE-2024-11918
The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the iat_add_alt_txt_action and iat_update_alt_txt_action AJAX actions in all versions up to, and including, 2.0.0. This makes ... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
4.3
MEDIUMCVE-2024-11154
The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-11143
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due to missing or incorrect nonce validation on the update_assistant, add_new_assistant, and delete_a... Read more
Affected Products : kognetiks_chatbot- Published: Nov. 13, 2024
- Modified: Nov. 18, 2024
-
4.3
MEDIUMCVE-2020-36743
The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.13. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possib... Read more
Affected Products : product_catalog_simple- Published: Jul. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-22731
Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Build Private Store For Woocommerce allows Cross Site Request Forgery.This issue affects Build Private Store For Woocommerce: from n/a through 1.0.... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-47059
When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Inva... Read more
Affected Products : mautic- Published: Sep. 18, 2024
- Modified: Feb. 27, 2025