41
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versions up to, and including, 0.4 due to insufficient input sanitization and output …
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13366
|
2025-01-17 16:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
42
|
5.3 |
MEDIUM
Network
-
|
-
|
The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.05 via the export functionality. The JSON files are stored in predictable…
New
|
CWE-200
Information Exposure
|
CVE-2024-12637
|
2025-01-17 16:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
43
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ parameter in all versions up to, and including, 1.0.8 due to insufficient input …
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-12598
|
2025-01-17 16:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
44
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'glofox_lead_capture ' shortcodes in all versions up to, and including, 2.6 due t…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-12508
|
2025-01-17 16:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
45
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.2.1.1 due to insufficient input sanitization an…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-12466
|
2025-01-17 16:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
46
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in all versions up to, and including, 5.2 due to insufficient input sanitization a…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-12203
|
2025-01-17 16:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
47
|
- |
|
-
|
-
|
TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is…
New
|
-
|
CVE-2024-11146
|
2025-01-17 16:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
48
|
7.5 |
HIGH
Network
|
-
|
-
|
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This m…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13333
|
2025-01-17 15:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
49
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function. This makes it possible for authentic…
New
|
CWE-22
Path Traversal
|
CVE-2024-10799
|
2025-01-17 15:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
50
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitiz…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13434
|
2025-01-17 14:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|