Latest CVE Feed
-
7.5
HIGHCVE-2024-44013
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through 2.4.0.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
4.9
MEDIUMCVE-2024-9146
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Low CSS JS Files allows Path Traversal.This issue affects CSS JS Files: from n/a through 1.5.0.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.4
MEDIUMCVE-2024-9455
The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.9
MEDIUMCVE-2024-47848
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Bypass.This issue affects Mediawiki - PageTriage: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from ... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.9
MEDIUMCVE-2024-47764
cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alte... Read more
Affected Products : cookie- Published: Oct. 04, 2024
- Modified: Oct. 07, 2024
-
6.6
MEDIUMCVE-2024-47309
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Condless Cities Shipping Zones for WooCommerce allows PHP Local File Inclusion.This issue affects Cities Shipping Zones for WooCommerce: from n/a through 1.2.7... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
9.6
CRITICALCVE-2024-44014
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmaxstudio Vmax Project Manager allows PHP Local File Inclusion, Code Injection.This issue affects Vmax Project Manager: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-44034
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX allows PHP Local File Inclusion.This issue affects WPSPX: from n/a through 1.0.2.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
5.9
MEDIUMCVE-2024-44042
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fahad Mahmood WP Datepicker allows Stored XSS.This issue affects WP Datepicker: from n/a through 2.1.1.... Read more
Affected Products : wp_datepicker- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-44024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NicheAddons Medical Addon for Elementor allows Stored XSS.This issue affects Medical Addon for Elementor: from n/a through 1.4.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-44028
Cross-Site Request Forgery (CSRF) vulnerability in Nicejob NiceJob allows Stored XSS.This issue affects NiceJob: from n/a before 3.6.5.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
5.9
MEDIUMCVE-2024-47336
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vladimir Statsenko Terms descriptions allows Stored XSS.This issue affects Terms descriptions: from n/a through 3.4.6.... Read more
Affected Products : terms_descriptions- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-47365
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a t... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47326
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ILLID Share This Image allows Reflected XSS.This issue affects Share This Image: from n/a through 2.01.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-47393
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Quillforms Quill Forms allows Stored XSS.This issue affects Quill Forms: from n/a through 3.7.0.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-47375
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ashraf XLTab – Accordions and Tabs for Elementor Page Builder allows Stored XSS.This issue affects XLTab – Accordions and Tabs for Elementor Page ... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47333
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Tangible Loops & Logic allows Reflected XSS.This issue affects Loops & Logic: from n/a through 4.1.4.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47380
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for eBay allows Reflected XSS.This issue affects WP-Lister Lite for eBay: from n/a through 3.6.3.... Read more
Affected Products : wp-lister_lite_for_ebay- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-47343
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.2.4.... Read more
Affected Products : mega_elements- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47301
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bit Form Bit Form – Contact Form Plugin allows Stored XSS.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024