Latest CVE Feed
-
5.5
MEDIUMCVE-2024-9462
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions up to, and including, 5.4.6 due to insufficient input sanitization and output escaping. This ma... Read more
Affected Products : poll_maker- Published: Oct. 26, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-9454
The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, ... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
6.4
MEDIUMCVE-2024-10091
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attr... Read more
- Published: Oct. 26, 2024
- Modified: Jan. 16, 2025
-
9.1
CRITICALCVE-2024-47821
pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain actions are completed, for e.g. a download is finished. By downloading a executable file to a folder in /scripts and performing the res... Read more
Affected Products : pyload- Published: Oct. 25, 2024
- Modified: Oct. 28, 2024
-
4.8
MEDIUMCVE-2024-48239
An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).... Read more
Affected Products : wtcms- Published: Oct. 25, 2024
- Modified: Apr. 17, 2025
-
4.7
MEDIUMCVE-2024-48238
WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.... Read more
Affected Products : wtcms- Published: Oct. 25, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-48237
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.... Read more
Affected Products : wtcms- Published: Oct. 25, 2024
- Modified: Apr. 17, 2025
-
6.5
MEDIUMCVE-2024-48236
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file... Read more
Affected Products : ofcms- Published: Oct. 25, 2024
- Modified: Apr. 18, 2025
-
6.5
MEDIUMCVE-2024-48235
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.... Read more
Affected Products : ofcms- Published: Oct. 25, 2024
- Modified: Apr. 18, 2025
-
4.9
MEDIUMCVE-2024-48234
An issue was discovered in mipjz 5.0.5. In the push method of app\tag\controller\ApiAdminTag.php the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in Server-side request forgery (... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 29, 2024
-
6.1
MEDIUMCVE-2024-48228
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Jun. 10, 2025
-
6.1
MEDIUMCVE-2024-48396
AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading ... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 30, 2024
-
4.8
MEDIUMCVE-2024-48233
mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP parameter.... Read more
Affected Products : mipjz- Published: Oct. 25, 2024
- Modified: Jul. 07, 2025
-
4.9
MEDIUMCVE-2024-48232
An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request fo... Read more
Affected Products : mipjz- Published: Oct. 25, 2024
- Modified: Jul. 07, 2025
-
9.8
CRITICALCVE-2024-48230
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48229
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-48227
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48226
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.1
CRITICALCVE-2024-48225
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-48224
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024