NA - CVE-2024-56361 - LGSL (Live Game Server List) provides online...
LGSL (Live Game Server List) provides online status for games. Before 7.0.0, a stored cross-site scripting (XSS) vulnerability was identified in lgsl. The function lgsl_query_40 in...
NA - CVE-2024-12969 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/index.php...
Medium - CVE-2024-12032 - The Tourfic – Ultimate Hotel Booking, Travel...
The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via the 'enquiry_id'...
Medium - CVE-2024-12190 - The Contact Form by Bit Form: Multi Step Form,...
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to...
High - CVE-2024-12272 - The WP Travel Engine – Elementor Widgets |...
The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
Medium - CVE-2024-12413 - The MarketKing — Ultimate WooCommerce...
The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like...
High - CVE-2024-12428 - The WP Data Access – App, Table, Form and Chart...
The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via the 'order[user_login][dir]' parameter in all versions up to, and...
Medium - CVE-2024-12636 - The Privacy Policy Generator, Terms &...
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
NA - CVE-2024-10858 - The Jetpack WordPress plugin before 14.1 does...
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites...