NA - CVE-2024-42180 - HCL MyXalytics is affected by a malicious file...
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special...
NA - CVE-2024-42181 - HCL MyXalytics is affected by a cleartext...
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel...
NA - CVE-2025-0399 - A vulnerability was found in StarSea99...
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController of the file...
NA - CVE-2025-0400 - A vulnerability was found in StarSea99...
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/categories/update. The manipulation of the...
Medium - CVE-2024-11327 - The ClickWhale – Link Manager, Link Shortener...
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg...
Medium - CVE-2024-12204 - The Coupon X: Discount Pop Up, Promo Code Pop...
The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several...
High - CVE-2024-12404 - The CF Internal Link Shortcode plugin for...
The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.1.0 due to insufficient escaping...
Medium - CVE-2024-12472 - The Post Duplicator plugin for WordPress is...
The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the mtphr_duplicate_post() due to insufficient restrictions on which...
Medium - CVE-2024-12505 - The Trackserver plugin for WordPress is...
The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in all versions up to, and including, 5.0.2 due to insufficient...
High - CVE-2024-12627 - The Coupon X: Discount Pop Up, Promo Code Pop...
The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.5 via...