2021
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Test Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8664
|
2024-09-13 16:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2022
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Simple Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all v…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8663
|
2024-09-13 16:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2023
|
- |
|
-
|
-
|
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(…
|
CWE-862
Missing Authorization
|
CVE-2024-7888
|
2024-09-13 16:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2024
|
- |
|
-
|
-
|
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to insufficient input sanitization and output escapi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5567
|
2024-09-13 16:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2025
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience
|
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
|
CWE-79
Cross-site Scripting
|
CVE-2024-7939
|
2024-09-13 16:15 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2026
|
5.4 |
MEDIUM
Network
|
3ds
|
3dexperience
|
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
|
CWE-79
Cross-site Scripting
|
CVE-2024-7932
|
2024-09-13 16:15 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2027
|
- |
|
-
|
-
|
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitra…
|
-
|
CVE-2024-7864
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2028
|
- |
|
-
|
-
|
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary f…
|
-
|
CVE-2024-7863
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2029
|
- |
|
-
|
-
|
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputtin…
|
-
|
CVE-2024-7133
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2030
|
- |
|
-
|
-
|
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injec…
|
-
|
CVE-2024-7129
|
2024-09-13 15:15 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|