NA - CVE-2024-12587 - The Contact Form Master WordPress plugin...
The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be...
NA - CVE-2024-42170 - HCL MyXalytics is affected by a session...
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.
NA - CVE-2024-42171 - HCL MyXalytics is affected by a session...
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's login session.
NA - CVE-2024-42172 - HCL MyXalytics is affected by broken...
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This...
NA - CVE-2024-42173 - HCL MyXalytics is affected by an improper...
HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the...
NA - CVE-2024-42174 - HCL MyXalytics is affected by username...
HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid usernames.
Medium - CVE-2024-11386 - The GatorMail SmartForms plugin for WordPress...
The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsmartform' shortcode in all versions up to, and including, 1.1.0...
Medium - CVE-2024-11758 - The WP SPID Italia plugin for WordPress is...
The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization...
Medium - CVE-2024-11874 - The Grid Accordion Lite plugin for WordPress is...
The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordion' shortcode in all versions up to, and including, 1.5.1 due...
Medium - CVE-2024-11892 - The Accordion Slider Lite plugin for WordPress...
The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_slider' shortcode in all versions up to, and including, 1.5.1...