Latest CVE Feed
-
7.1
HIGHCVE-2024-43220
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.26.... Read more
Affected Products : form_maker- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43123
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Techeshta Card Elements for Elementor allows Stored XSS.This issue affects Card Elements for Elementor: from n/a through 1.2.2.... Read more
Affected Products : card_elements_for_elementor- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43224
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yuri Baranov YaMaps for WordPress allows Stored XSS.This issue affects YaMaps for WordPress: from n/a through 0.6.27.... Read more
Affected Products : yamaps- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43227
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8.... Read more
Affected Products : betterdocs- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43164
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Blockspare allows Stored XSS.This issue affects Blockspare: from n/a through 3.2.0.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.5
HIGHCVE-2024-38747
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects HitPay Payment Gateway f... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-7094
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of saniti... Read more
Affected Products : js_help_desk- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
5.1
MEDIUMCVE-2024-39922
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions), LOGO! 24CE... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-38752
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campaigns allows Cross-Site Scripting (XSS).This issue affects Zoho Campaigns: from n/a through 2.0.8.... Read more
Affected Products : zoho_campaigns- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-38756
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-43127
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPFactory Products, Order & Customers Export for WooCommerce allows Reflected XSS.This issue affects Products, Order & Customers Export for WooCom... Read more
Affected Products : products\,_order_\&_customers_export_for_woocommerce- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43149
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.7.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43124
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Iqonic Design Graphina allows Stored XSS.This issue affects Graphina: from n/a through 1.8.10.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.9
MEDIUMCVE-2024-35775
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vulnerability in Soliloquy Team Slider by Soliloquy allows Cross-Site Scripting (XSS).This issue affects Slider by Soliloquy: from n/a thr... Read more
Affected Products : slider- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.9
MEDIUMCVE-2024-43137
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WappPress Team WappPress allows Stored XSS.This issue affects WappPress: from n/a through 6.0.4.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-38742
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MBE eShip: from n/a through 2.1.2.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-39642
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LearnPress: from n/a through 4.2.6.8.2.... Read more
Affected Products : learnpress- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43226
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects WP Dashboard Notes: from n/a through 1.0.11.... Read more
Affected Products : wp_dashboard_notes- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-38760
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Send Users Email: from n/a through 1.5.1.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-43217
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes allows Reflected XSS.This issue affects Kodex Posts likes: from n/a through 2.5.0.... Read more
Affected Products : kodex_posts_likes- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024