NA - CVE-2024-11626 - Improper Neutralization of Input During CMS...
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects...
NA - CVE-2024-11627 - : Insufficient Session Expiration vulnerability...
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from...
Medium - CVE-2024-12077 - The Booking Calendar and Booking Calendar Pro...
The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘calendar_id’ parameter in all versions up to, and including, 3.2.19 and...
High - CVE-2024-12202 - The Croma Music plugin for WordPress is...
The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'ironMusic_ajax'...
Medium - CVE-2024-12516 - The Coupon Plugin plugin for WordPress is...
The Coupon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Coupon Code' parameter in all versions up to, and including, 1.2.1 due to insufficient input...
High - CVE-2024-12152 - The MIPL WC Multisite Sync plugin for WordPress...
The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.5 via the 'mipl_wc_sync_download_log' action. This makes it...
Medium - CVE-2024-12699 - The Service Box plugin for WordPress is...
The Service Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it...