|
313301
|
9.0 |
CRITICAL
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due …
|
CWE-22
Path Traversal
|
CVE-2024-7777
|
2024-08-27 03:19 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313302
|
7.2 |
HIGH
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id para…
|
CWE-89
SQL Injection
|
CVE-2024-7780
|
2024-08-27 03:19 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313303
|
4.8 |
MEDIUM
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7775
|
2024-08-27 03:18 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313304
|
7.2 |
HIGH
Network
|
bitapps
|
contact_form_builder
|
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID…
|
CWE-89
SQL Injection
|
CVE-2024-7702
|
2024-08-27 03:15 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313305
|
5.4 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function…
|
CWE-862
Missing Authorization
|
CVE-2024-5941
|
2024-08-27 03:14 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313306
|
5.3 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all…
|
CWE-862
Missing Authorization
|
CVE-2024-5940
|
2024-08-27 03:14 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313307
|
5.3 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all version…
|
CWE-862
Missing Authorization
|
CVE-2024-5939
|
2024-08-27 03:12 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313308
|
- |
|
-
|
-
|
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing an Authority Key …
|
-
|
CVE-2024-45235
|
2024-08-27 02:35 |
2024-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313309
|
- |
|
-
|
-
|
A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the templa…
|
-
|
CVE-2024-40111
|
2024-08-27 02:35 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313310
|
- |
|
-
|
-
|
A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible …
|
-
|
CVE-2024-42914
|
2024-08-27 02:35 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|