Latest CVE Feed
-
6.3
MEDIUMCVE-2025-24389
Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OT... Read more
Affected Products : otrs- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2024-43446
An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * (... Read more
Affected Products : otrs- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-43445
A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or inserting content that would be treated as a different ... Read more
Affected Products : otrs- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-13117
The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded... Read more
- Published: Jan. 27, 2025
- Modified: May. 13, 2025
- Vuln Type: Authentication
-
3.8
LOWCVE-2024-13116
The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : crelly_slider- Published: Jan. 27, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13095
The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : wp_triggers_lite- Published: Jan. 27, 2025
- Modified: May. 05, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-13094
The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : wp_triggers_lite- Published: Jan. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13057
The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.... Read more
Affected Products : dyn_business_panel- Published: Jan. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2024-13056
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : dyn_business_panel- Published: Jan. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13055
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : dyn_business_panel- Published: Jan. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13052
The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as ad... Read more
Affected Products : dental_optimizer_patient_generator_app- Published: Jan. 27, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-12774
The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack... Read more
Affected Products : altra_side_menu- Published: Jan. 27, 2025
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2024-12773
The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : altra_side_menu- Published: Jan. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-12436
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks... Read more
Affected Products : wp_customer_area- Published: Jan. 27, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2024-12321
The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : wc_affiliate- Published: Jan. 27, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-12280
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack... Read more
Affected Products : wp_customer_area- Published: Jan. 27, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2024-28771
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-28770
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-28766
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2023-46187
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede... Read more
- Published: Jan. 27, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting