NA - CVE-2024-31141 - Files or Directories Accessible to External...
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior,...
High - CVE-2024-11036 - The The GamiPress – The #1 gamification plugin...
The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via...
High - CVE-2024-11038 - The The WPB Popup for Contact Form 7 – Showing...
The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_fire_contact_form...
NA - CVE-2024-11195 - The Email Subscription Popup plugin for...
The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including,...
High - CVE-2024-11194 - The Classified Listing – Classified ads &...
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a...
Medium - CVE-2024-11198 - The GD Rating System plugin for WordPress is...
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input...
Medium - CVE-2024-11224 - The Parallax Image plugin for WordPress is...
The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization...
Medium - CVE-2024-9777 - The Ashe theme for WordPress is vulnerable to...
The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243....
NA - CVE-2024-9830 - The Bard theme for WordPress is vulnerable to...
The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.216....