Medium - CVE-2024-8760 - The Stackable – Page Builder Gutenberg Blocks...
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers...
Medium - CVE-2024-8915 - The Category Icon plugin for WordPress is...
The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and...
Medium - CVE-2024-9595 - The TablePress – Tables in WordPress made easy...
The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to...
Medium - CVE-2024-9696 - The Rescue Shortcodes plugin for WordPress is...
The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 due to...
High - CVE-2024-8757 - The WP Post Author – Boost Your Blog's...
The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress...
NA - CVE-2024-8902 - The Elementor Addon Elements plugin for...
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in...
NA - CVE-2024-9894 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file reset.php. The manipulation of the argument...
NA - CVE-2024-49193 - Zendesk before 2024-07-02 allows remote...
Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional...
NA - CVE-2024-9903 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of...
Critical - CVE-2024-9822 - The Pedalo Connector plugin for WordPress is...
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user'...