NA - CVE-2023-29476 - In Menlo On-Premise Appliance before 2.88, web...
In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+.
Medium - CVE-2024-11095 - The Visualmodo Elements plugin for WordPress is...
The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input...
Medium - CVE-2024-11462 - The Filestack Official plugin for WordPress is...
The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filestack_options' parameters in all versions up to, and...
Medium - CVE-2024-11751 - The TCBD Popover plugin for WordPress is...
The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image ' shortcode in all versions up to, and including, 1.2 due to...
Medium - CVE-2024-11755 - The IMS Countdown plugin for WordPress is...
The IMS Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown post settings in all versions up to, and including, 1.3.4 due to insufficient input...
Medium - CVE-2024-11759 - The Bukza plugin for WordPress is vulnerable to...
The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all versions up to, and including, 2.0.0 due to insufficient input...
Medium - CVE-2024-11763 - The Plezi plugin for WordPress is vulnerable to...
The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all versions up to, and including, 1.0.6 due to insufficient input...
Medium - CVE-2024-11770 - The Post Carousel & Slider plugin for WordPress...
The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' shortcode in all versions up to, and including, 1.0.4 due to...
Medium - CVE-2024-11855 - The Koalendar – Events & Appointments Booking...
The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.0.2 due...
Medium - CVE-2024-11865 - The Tabs Maker plugin for WordPress is...
The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on tab...