Medium - CVE-2024-13648 - The Maps for WP plugin for WordPress is...
The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortcode in all versions up to, and including, 1.2.4 due to...
NA - CVE-2025-1470 - In Eclipse OMR, from the initial contribution...
In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for NULL memory...
NA - CVE-2025-1471 - In Eclipse OMR versions 0.2.0 to 0.4.0, some of...
In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer...
Medium - CVE-2024-13455 - The igumbi Online Booking plugin for WordPress...
The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_calendar' shortcode in all versions up to, and including, 1.40...
Medium - CVE-2024-13713 - The WPExperts Square For GiveWP plugin for...
The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on...
Medium - CVE-2024-13846 - The Indeed Ultimate Learning Pro plugin for...
The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insufficient escaping on...
Medium - CVE-2024-13900 - The Head, Footer and Post Injections plugin for...
The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with...
NA - CVE-2024-9150 - Report generation functionality in Wyn...
Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to...
Medium - CVE-2025-1402 - The Event Tickets and Registration plugin for...
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions...
Medium - CVE-2025-1489 - The WP-Appbox plugin for WordPress is...
The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due to insufficient input...