1101
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in several widgets in all ve…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13354
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1102
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tmpcoder_theme_install…
|
CWE-862
Missing Authorization
|
CVE-2024-13335
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1103
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_sgwf' shortcode in all versions up to, and including, 2.0 due to insufficient i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13583
|
2025-01-24 19:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1104
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_map' shortcode in all versions up to, and including, 2.6.1 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12494
|
2025-01-24 19:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1105
|
9.8 |
CRITICAL
Network
-
|
-
|
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attacke…
|
CWE-22
Path Traversal
|
CVE-2024-13545
|
2025-01-24 18:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1106
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation o…
|
CWE-352
Origin Validation Error
|
CVE-2024-13683
|
2025-01-24 16:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1107
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in all versions up to, and including, 1.2.41 due to ins…
|
CWE-89
SQL Injection
|
CVE-2024-13680
|
2025-01-24 16:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1108
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortcode in all versions up to, and including, 2.3.4 due to insufficient input saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13659
|
2025-01-24 15:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1109
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site sc…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0314
|
2025-01-24 12:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1110
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have…
|
CWE-1220
Insufficient Granularity of Access Control
|
CVE-2024-11931
|
2025-01-24 12:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|