561
|
- |
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG file containing a …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-3742
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
562
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malic…
|
CWE-79
Cross-site Scripting
|
CVE-2021-3741
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
563
|
- |
|
-
|
-
|
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowi…
|
CWE-384
Session Fixation
|
CVE-2021-3740
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
564
|
8.0 |
HIGH
Network
|
-
|
-
|
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …
|
CWE-200
Information Exposure
|
CVE-2024-8979
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
565
|
5.7 |
MEDIUM
Network
|
-
|
-
|
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …
|
-
|
CVE-2024-8978
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
566
|
7.5 |
HIGH
Network
|
-
|
-
|
The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_han…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-10311
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
567
|
- |
|
-
|
-
|
The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from runn…
|
-
|
CVE-2024-9529
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
568
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8961
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
569
|
- |
|
-
|
-
|
The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10825
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
570
|
- |
|
-
|
-
|
The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting att…
|
-
|
CVE-2024-10104
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|