Medium - CVE-2024-13551 - The ABC Notation plugin for WordPress is...
The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in all versions up to, and including, 6.1.3 due to insufficient...
Medium - CVE-2024-13586 - The Masy Gallery plugin for WordPress is...
The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' shortcode in all versions up to, and including, 1.7 due to...
Medium - CVE-2024-13599 - The LearnPress – WordPress LMS Plugin plugin...
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and...
Medium - CVE-2024-13449 - The Boom Fest plugin for WordPress is...
The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bf_admin_action' function in all versions up to, and...
Low - CVE-2024-13450 - The Contact Form by Bit Form: Multi Step Form,...
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Medium - CVE-2025-0350 - The Divi Carousel Maker – Image, Logo,...
The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Carousel and Logo Carousel in...
NA - CVE-2025-24360 - Nuxt is an open-source web development...
Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt allows any websites to send any requests to the development server and read...
NA - CVE-2025-24361 - Nuxt is an open-source web development...
Nuxt is an open-source web development framework for Vue.js. Source code may be stolen during dev when using version 3.0.0 through 3.15.12 of the webpack builder or version 3.12.2 through 3.152 of...
Critical - CVE-2025-0357 - The WPBookit plugin for WordPress is vulnerable...
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in...
Medium - CVE-2024-13709 - The Linear plugin for WordPress is vulnerable...
The Linear plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on the...