841
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php.…
|
-
|
CVE-2025-0537
|
2025-01-18 18:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
842
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13392
|
2025-01-18 17:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
843
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing ca…
|
CWE-862
Missing Authorization
|
CVE-2025-0515
|
2025-01-18 16:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
844
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and out…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0369
|
2025-01-18 16:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
845
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13519
|
2025-01-18 16:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
846
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in all versions up to, and including,…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13517
|
2025-01-18 16:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
847
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13433
|
2025-01-18 16:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
848
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on a function. Thi…
|
CWE-352
Origin Validation Error
|
CVE-2024-13432
|
2025-01-18 16:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
849
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_videos' shortcode in all versions up to, and i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13393
|
2025-01-18 16:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
850
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_up…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13391
|
2025-01-18 16:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|