681
|
- |
|
-
|
-
|
util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.
|
-
|
CVE-2024-47855
|
2024-10-4 15:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
682
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medium_posts shortcode in all versions up to, and including, 5.0.1 due to insuffici…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9445
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
683
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitizati…
|
-
|
CVE-2024-9421
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
684
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9384
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
685
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versio…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9375
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
686
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9372
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
687
|
- |
|
-
|
-
|
The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9368
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
688
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9353
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
689
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9349
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
690
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all ve…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9345
|
2024-10-4 14:15 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|