Latest CVE Feed
-
8.1
HIGHCVE-2024-47323
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin allows PHP Local File Inclusion.This issue affects WP Timeline – Vertical and Horizontal timeli... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.8
MEDIUMCVE-2024-8743
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed f... Read more
Affected Products : file_manager- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
8.0
HIGHCVE-2024-47319
Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form – Contact Form Plugin allows Code Injection.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.... Read more
Affected Products : bit_form- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-44012
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Subscription allows PHP Local File Inclusion.This issue affects WP Newsletter Subscription: from n/a through 1.1.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-44011
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Ticket Ultra WP Ticket Ultra Help Desk & Support Plugin allows PHP Local File Inclusion.This issue affects WP Ticket Ultra Help Desk & Support Plugin: from ... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.9
MEDIUMCVE-2024-47764
cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alte... Read more
Affected Products : cookie- Published: Oct. 04, 2024
- Modified: Oct. 07, 2024
-
6.9
MEDIUMCVE-2024-47848
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Bypass.This issue affects Mediawiki - PageTriage: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from ... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
5.9
MEDIUMCVE-2024-44040
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Plainware ShiftController Employee Shift Scheduling allows Stored XSS.This issue affects ShiftController Employee Shift Scheduling: from n/a throu... Read more
Affected Products : shiftcontroller- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
5.1
MEDIUMCVE-2024-44010
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Catch Themes Full frame allows Stored XSS.This issue affects Full frame: from n/a through 2.7.2.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47369
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Social Auto Poster allows Reflected XSS.This issue affects Social Auto Poster: from n/a through 5.3.15.... Read more
Affected Products : social_auto_poster- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47301
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bit Form Bit Form – Contact Form Plugin allows Stored XSS.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47322
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin allows Reflected XSS.This issue affects WP Timeline – Vertical and Horizontal time... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-47373
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 6.5.0.2.... Read more
Affected Products : litespeed_cache- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
5.9
MEDIUMCVE-2024-44036
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes allows Stored XSS.This issue affects Kodex Posts likes: from n/a through 2.5.0.... Read more
Affected Products : kodex_posts_likes- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.8
HIGHCVE-2024-45245
Diebold Nixdorf – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
5.9
MEDIUMCVE-2024-47377
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeKraft BuddyForms allows Stored XSS.This issue affects BuddyForms: from n/a through 2.8.12.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47320
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WS Form WS Form LITE allows Stored XSS.This issue affects WS Form LITE: from n/a through 1.9.238.... Read more
Affected Products : ws_form- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47349
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMobile.App allows Reflected XSS.This issue affects WPMobile.App: from n/a through 11.50.... Read more
- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
5.9
MEDIUMCVE-2024-44039
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Travel allows Stored XSS.This issue affects WP Travel: from n/a through 9.3.1.... Read more
Affected Products : wp_travel- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-47630
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS.This issue affects ElementInvader Addons for Elementor: from n/a through 1.2.... Read more
Affected Products : elementinvader_addons_for_elementor- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024