Latest CVE Feed
-
6.5
MEDIUMCVE-2024-54224
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows DOM-Based XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.7.... Read more
Affected Products : elementsready- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.3
MEDIUMCVE-2024-54223
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Contact Form - Repute InfoSystems ARForms Form Builder allows Code Injection.This issue affects ARForms Form Builder: from n/a through 1.7.1.... Read more
Affected Products : arforms_form_builder- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
7.1
HIGHCVE-2024-54220
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roninwp FAT Services Booking allows Stored XSS.This issue affects FAT Services Booking: from n/a through 5.6.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
7.1
HIGHCVE-2024-54219
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thehp AIO Contact.This issue affects AIO Contact: from n/a through 2.8.1.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2024-54217
Missing Authorization vulnerability in Repute info systems ARForms.This issue affects ARForms: from n/a through 6.4.1.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
9.3
CRITICALCVE-2024-54215
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roninwp Revy.This issue affects Revy: from n/a through 1.18.... Read more
Affected Products : revy- Published: Dec. 09, 2024
- Modified: Dec. 20, 2024
-
10.0
CRITICALCVE-2024-53822
Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.... Read more
Affected Products : pie_register- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.3
MEDIUMCVE-2024-53819
Missing Authorization vulnerability in Sprout Invoices Client Invoicing by Sprout Invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through 20.8.0.... Read more
Affected Products : client_invoicing_by_sprout_invoices- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
6.5
MEDIUMCVE-2024-53818
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post Grid Team by WPXPO PostX allows Stored XSS.This issue affects PostX: from n/a through 4.1.15.... Read more
Affected Products : postx- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
8.8
HIGHCVE-2024-53816
Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons.This issue affects Tutor LMS Elementor Addons: from n/a through 2.1.5.... Read more
Affected Products : tutor_lms_elementor_addons- Published: Dec. 09, 2024
- Modified: Feb. 03, 2025
-
5.4
MEDIUMCVE-2024-53798
Missing Authorization vulnerability in BAKKBONE Australia FloristPress.This issue affects FloristPress: from n/a through 7.3.0.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
6.5
MEDIUMCVE-2024-53791
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS allows Stored XSS.This issue affects Lenxel Core for Lenxel(LNX) LMS: from n/a through 1.2.5.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
7.5
HIGHCVE-2024-53790
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS.This issue affects Lenxel Core for Lenxel(LNX) LMS: from n/a through 1.2.5.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2024-53785
Missing Authorization vulnerability in Alexander Volkov Chatter.This issue affects Chatter: from n/a through 1.0.1.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2024-43222
Missing Authorization vulnerability in SeventhQueen Sweet Date.This issue affects Sweet Date: from n/a through 3.7.3.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 20, 2024
-
5.3
MEDIUMCVE-2023-51362
Missing Authorization vulnerability in Premio All-in-one Floating Contact Form – My Sticky Elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All-in-one Floating Contact Form – My Sticky Elements: from n/a ... Read more
Affected Products : mystickyelements- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
8.8
HIGHCVE-2023-51360
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.... Read more
Affected Products : essential_blocks- Published: Dec. 09, 2024
- Modified: Jan. 22, 2025
-
8.8
HIGHCVE-2023-51359
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.... Read more
Affected Products : essential_blocks- Published: Dec. 09, 2024
- Modified: Jan. 22, 2025
-
5.3
MEDIUMCVE-2023-51357
Missing Authorization vulnerability in Conversios Conversios.io allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conversios.io: from n/a through 6.5.0.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
8.2
HIGHCVE-2023-51355
Missing Authorization vulnerability in MultiVendorX WC Marketplace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Marketplace: from n/a through 4.0.23.... Read more
Affected Products : multivendorx- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024