NA - CVE-2024-12586 - The Chalet-Montagne.com Tools WordPress plugin...
The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could...
NA - CVE-2024-13119 - The Paid Membership Plugin, Ecommerce, User...
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which...
NA - CVE-2024-13120 - The Paid Membership Plugin, Ecommerce, User...
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which...
NA - CVE-2024-13121 - The Paid Membership Plugin, Ecommerce, User...
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which...
NA - CVE-2024-13125 - The Everest Forms WordPress plugin before...
The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2025-0692 - The Simple Video Management System WordPress...
The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored...
NA - CVE-2025-1059 - CWE-770: Allocation of Resources Without Limits...
CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious packets are sent to the webserver of the device.
NA - CVE-2025-1060 - CWE-319: Cleartext Transmission of Sensitive...
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.
NA - CVE-2025-1070 - CWE-434: Unrestricted Upload of File with...
CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downloaded.