Latest CVE Feed
-
4.3
MEDIUMCVE-2024-13607
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled k... Read more
Affected Products : js_help_desk- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2024-12597
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output esca... Read more
Affected Products : ht_mega- Published: Feb. 04, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-0466
The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.... Read more
Affected Products : sensei_lms- Published: Feb. 04, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-0368
The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unaut... Read more
Affected Products : banner_garden- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13332
The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : transfinanz- Published: Feb. 04, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13331
The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : wp_dream_carousel- Published: Feb. 04, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13330
The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : justrows_free- Published: Feb. 04, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13329
The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : solidres- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13328
The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : giga_messenger- Published: Feb. 04, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13327
The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : musicbox- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13326
The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : ibuildapp- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13325
The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : glossy- Published: Feb. 04, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13115
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSR... Read more
Affected Products : wp_projects_portfolio_with_client_testimonials- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2024-13114
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users su... Read more
Affected Products : wp_projects_portfolio_with_client_testimonials- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-24982
Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-22475
Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote attacker could potentially exploit this vulnerability, leading to Information ta... Read more
Affected Products : data_domain_operating_system- Published: Feb. 04, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Cryptography
-
8.5
HIGHCVE-2025-1003
A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass which may result in escalation of privilege. HP is releasing a software update to mitigate this potential vulnerability.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authentication
-
2.6
LOWCVE-2025-0148
Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.... Read more
Affected Products :- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Information Disclosure
-
9.4
CRITICALCVE-2025-24958
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_tag.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access t... Read more
Affected Products : wegia- Published: Feb. 03, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-24957
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_detalhes_socio.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing ... Read more
Affected Products : wegia- Published: Feb. 03, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Injection