1071
|
6.1 |
MEDIUM
Network
|
wpbookingsystem
|
wp_booking_system
|
The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the UR…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8797
|
2024-09-27 23:02 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1072
|
5.4 |
MEDIUM
Network
|
bricksbuilder
|
bricks
|
The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up to, and including, 1.10.1 due to insufficient input sanitization and output es…
|
CWE-79
Cross-site Scripting
|
CVE-2023-3410
|
2024-09-27 22:58 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1073
|
8.8 |
HIGH
Network
|
idehweb
|
login_with_phone_number
|
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check o…
|
NVD-CWE-noinfo
|
CVE-2024-6482
|
2024-09-27 22:54 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1074
|
5.5 |
MEDIUM
Network
|
ibericode
|
mailchimp
|
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitiza…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8680
|
2024-09-27 22:53 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1075
|
6.1 |
MEDIUM
Network
|
github
|
enterprise_server
|
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social enginee…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8770
|
2024-09-27 22:49 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1076
|
6.1 |
MEDIUM
Network
|
boopathirajan
|
wp_test_email
|
The WP Test Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8664
|
2024-09-27 22:48 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1077
|
7.8 |
HIGH
Local
|
google
|
chrome
|
Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Low)
|
NVD-CWE-noinfo
|
CVE-2018-20072
|
2024-09-27 22:46 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1078
|
4.3 |
MEDIUM
Network
|
radiustheme
|
classified_listing_-_classified_ads_\&_business_directory
|
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(…
|
CWE-862
Missing Authorization
|
CVE-2024-7888
|
2024-09-27 22:45 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1079
|
8.8 |
HIGH
Network
|
wpml
|
wpml
|
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation …
|
CWE-94
Code Injection
|
CVE-2024-6386
|
2024-09-27 22:25 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1080
|
8.8 |
HIGH
Network
|
acymailing
|
acymailing
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7384
|
2024-09-27 22:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|