Latest CVE Feed
-
4.6
MEDIUMCVE-2024-49502
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. Th... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.3
HIGHCVE-2024-22038
Various problems in obs-scm-bridge allows attackers that create specially crafted git repositories to leak information of cause denial of service.... Read more
Affected Products : opensuse_factory- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
5.7
MEDIUMCVE-2024-22037
The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
8.2
HIGHCVE-2024-11599
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.... Read more
- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
9.8
CRITICALCVE-2024-11103
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This ma... Read more
Affected Products : contest_gallery- Published: Nov. 28, 2024
- Modified: Apr. 11, 2025
-
9.9
CRITICALCVE-2024-11082
The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attac... Read more
Affected Products : tumult_hype_animations- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
4.3
MEDIUMCVE-2024-10798
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes... Read more
Affected Products : royal_elementor_addons- Published: Nov. 28, 2024
- Modified: Mar. 04, 2025
-
4.3
MEDIUMCVE-2024-10780
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the 'narestaurant_elementor_template' shortcode due to insufficient restrictions on which posts can be inc... Read more
Affected Products : restaurant_\&_cafe_addon_for_elementor- Published: Nov. 28, 2024
- Modified: Jul. 14, 2025
-
4.3
MEDIUMCVE-2024-10670
The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.2 via the [prim_elementor_template] shortcode due to insufficient restrictions on which posts can be included. This makes ... Read more
Affected Products : primary_addon_for_elementor- Published: Nov. 28, 2024
- Modified: Apr. 11, 2025
-
7.2
HIGHCVE-2024-9669
The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level a... Read more
Affected Products : filester- Published: Nov. 28, 2024
- Modified: Feb. 26, 2025
-
8.8
HIGHCVE-2024-8066
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subs... Read more
Affected Products : filester- Published: Nov. 28, 2024
- Modified: Feb. 26, 2025
-
6.4
MEDIUMCVE-2024-11788
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.4
MEDIUMCVE-2024-11786
The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'continue-with-vipps' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.4
MEDIUMCVE-2024-11761
The LegalWeb Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'legalweb-popup' shortcode in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attrib... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.1
MEDIUMCVE-2024-11685
The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. Thi... Read more
Affected Products : kudos_donations- Published: Nov. 28, 2024
- Modified: Jul. 16, 2025
-
6.1
MEDIUMCVE-2024-11684
The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping... Read more
Affected Products : kudos_donations- Published: Nov. 28, 2024
- Modified: Jul. 14, 2025
-
6.1
MEDIUMCVE-2024-11458
The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for una... Read more
Affected Products : faq_builder- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.4
MEDIUMCVE-2024-11431
The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.1
MEDIUMCVE-2024-11366
The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.66.2. This makes it possible for unauthenti... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.4
MEDIUMCVE-2024-11333
The HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hls_player' shortcode in all versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. T... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024