191
|
6.1 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-3866
|
2024-10-3 03:26 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
192
|
8.8 |
HIGH
Network
|
wclovers
|
frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible
|
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8290
|
2024-10-3 03:23 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
193
|
- |
|
-
|
-
|
A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special …
New
|
-
|
CVE-2024-24122
|
2024-10-3 03:15 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
194
|
5.4 |
MEDIUM
Network
|
braginteractive
|
material_design_icons
|
The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon shortcode in all versions up to, and including, 0.0.5 due to insufficient input s…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-9024
|
2024-10-3 03:02 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
195
|
7.3 |
HIGH
Network
blogcoding
|
special_text_boxes
|
The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.2. This is due to the plugin adding the filter add_filter('com…
Update
|
CWE-94
Code Injection
|
CVE-2024-8481
|
2024-10-3 02:59 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
196
|
7.5 |
HIGH
Network
jianbo
|
rest_api_to_miniprogram
|
The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to…
Update
|
CWE-89
SQL Injection
|
CVE-2024-8484
|
2024-10-3 02:44 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
197
|
4.8 |
MEDIUM
Network
|
technowich
|
wp_ulike
|
The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-6094
|
2024-10-3 02:44 |
2024-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
198
|
5.4 |
MEDIUM
Network
|
technowich
|
wp_ulike
|
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TechnoWich WP ULike – Most Advanced WordPress Marketing Toolkit plugin <= 4.6.8 versions.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2023-45640
|
2024-10-3 02:44 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
199
|
4.8 |
MEDIUM
Network
|
technowich
|
wp_ulike
|
The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-7878
|
2024-10-3 02:41 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
200
|
- |
|
-
|
-
|
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
New
|
-
|
CVE-2024-46626
|
2024-10-3 02:35 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|