CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2024-13311

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2024-13310

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-13309

    Last Modified: 28 Aug 2025

    Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.

    Published: 9 Jan 2025
    3.8
    Low

    CVE-2024-13308

    Last Modified: 5 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.

    Published: 9 Jan 2025
    4.8
    Medium

    CVE-2024-13305

    Last Modified: 28 Aug 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form Steps allows Cross-Site Scripting (XSS).This issue affects Entity Form Steps: from 0.0.0 before 1.1.4.

    Published: 9 Jan 2025
    4.5
    Medium

    CVE-2024-13304

    Last Modified: 28 Aug 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13303

    Last Modified: 2 Sept 2025

    Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13302

    Last Modified: 2 Sept 2025

    Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.

    Published: 9 Jan 2025
    6.1
    Medium

    CVE-2024-13301

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client): from 3.0.0 before 3.44.0, from 4.0.0 before 4.0.19.

    Published: 9 Jan 2025
    6.6
    Medium

    CVE-2024-13300

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Print Anything.This issue affects Print Anything: *.*.

    Published: 9 Jan 2025
    6.6
    Medium

    CVE-2024-13299

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Megamenu Framework.This issue affects Megamenu Framework: *.*.

    Published: 9 Jan 2025
    4.8
    Medium

    CVE-2024-13298

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Citron allows Cross-Site Scripting (XSS).This issue affects Tarte au Citron: from 2.0.0 before 2.0.5.

    Published: 9 Jan 2025
    6.6
    Medium

    CVE-2024-13297

    Last Modified: 3 Sept 2025

    Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.

    Published: 9 Jan 2025
    6.6
    Medium

    CVE-2024-13296

    Last Modified: 3 Sept 2025

    Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.

    Published: 9 Jan 2025
    6.6
    Medium

    CVE-2024-13295

    Last Modified: 2 Sept 2025

    Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-13294

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal POST File allows Cross-Site Scripting (XSS).This issue affects POST File: from 0.0.0 before 1.0.2.

    Published: 9 Jan 2025
    3.1
    Low

    CVE-2024-13293

    Last Modified: 2 Sept 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects POST File: from 0.0.0 before 1.0.2.

    Published: 9 Jan 2025
    4.8
    Medium

    CVE-2024-13292

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tooltip allows Cross-Site Scripting (XSS).This issue affects Tooltip: from 0.0.0 before 1.1.2.

    Published: 9 Jan 2025
    7.3
    High

    CVE-2024-13291

    Last Modified: 2 Sept 2025

    Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13290

    Last Modified: 2 Sept 2025

    Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-13289

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot + GTM allows Cross-Site Scripting (XSS).This issue affects Cookiebot + GTM: from 0.0.0 before 1.0.18.

    Published: 9 Jan 2025
    4.3
    Medium

    CVE-2024-13288

    Last Modified: 2 Sept 2025

    Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-13287

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG Animation allows Cross-Site Scripting (XSS).This issue affects Views SVG Animation: from 0.0.0 before 1.0.1.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-13286

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed allows Cross-Site Scripting (XSS).This issue affects SVG Embed: from 0.0.0 before 2.1.2.

    Published: 9 Jan 2025
    9.8
    Critical

    CVE-2024-13285

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22295

    Last Modified: 29 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tripetto WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto tripetto allows Stored XSS.This issue affects WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto: from n/a through <= 8.0.6.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22307

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Product Table for WooCommerce woo-product-table allows Reflected XSS.This issue affects Product Table for WooCommerce: from n/a through <= 4.0.3.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22313

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22330

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahesh Waghmare MG Parallax Slider mg-parallax-slider allows Reflected XSS.This issue affects MG Parallax Slider: from n/a through <= 1.0..

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22331

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in P3JX Cf7Save Extension cf7save-extension allows Reflected XSS.This issue affects Cf7Save Extension: from n/a through <= 1.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22345

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tsinf TS Comfort DB ts-comfort-database allows Reflected XSS.This issue affects TS Comfort DB: from n/a through <= 2.0.7.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22361

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Opentracker Opentracker Analytics opentracker-analytics allows Reflected XSS.This issue affects Opentracker Analytics: from n/a through <= 1.3.

    Published: 9 Jan 2025
    10
    Critical

    CVE-2025-22504

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in jumpdemand 4ECPS Web Forms 4ecps-webforms allows Upload a Web Shell to a Web Server.This issue affects 4ECPS Web Forms: from n/a through <= 0.2.18.

    Published: 9 Jan 2025
    8.5
    High

    CVE-2025-22505

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlist-for-woocommerce allows SQL Injection.This issue affects NC Wishlist for Woocommerce: from n/a through <= 1.0.1.

    Published: 9 Jan 2025
    8.1
    High

    CVE-2025-22508

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Event Lite fat-event-lite allows PHP Local File Inclusion.This issue affects FAT Event Lite: from n/a through <= 1.1.

    Published: 9 Jan 2025
    7.2
    High

    CVE-2025-22510

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through <= 2.1.4.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22521

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through <= 2.18.8.

    Published: 9 Jan 2025
    7.6
    High

    CVE-2025-22527

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows SQL Injection.This issue affects Mailing Group Listserv: from n/a through <= 2.0.9.

    Published: 9 Jan 2025
    8.5
    High

    CVE-2025-22535

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal wplistcal allows SQL Injection.This issue affects WPListCal: from n/a through <= 1.3.5.

    Published: 9 Jan 2025
    8.5
    High

    CVE-2025-22537

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google Maps Travel Route google-maps-travel-route allows SQL Injection.This issue affects Google Maps Travel Route: from n/a through <= 1.3.1.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22539

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBase Tables custom-database-tables allows Reflected XSS.This issue affects Custom DataBase Tables: from n/a through <= 2.1.34.

    Published: 9 Jan 2025
    9.3
    Critical

    CVE-2025-22540

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in seballero Emailing Subscription email-suscripcion allows Blind SQL Injection.This issue affects Emailing Subscription: from n/a through <= 1.4.1.

    Published: 9 Jan 2025
    9.3
    Critical

    CVE-2025-22542

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ofek Nakar Virtual Bot virtual-bot allows Blind SQL Injection.This issue affects Virtual Bot: from n/a through <= 1.0.0.

    Published: 9 Jan 2025
    4.3
    Medium

    CVE-2025-22561

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in kbowson Title Experiments Free wp-experiments-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Title Experiments Free: from n/a through <= 9.0.4.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22594

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder Better User Shortcodes better-user-shortcodes allows Reflected XSS.This issue affects Better User Shortcodes: from n/a through <= 1.0.

    Published: 9 Jan 2025
    7.1
    High

    CVE-2025-22595

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows Reflected XSS.This issue affects Mailing Group Listserv: from n/a through <= 2.0.9.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22801

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Free WooCommerce Theme 99fy Extension 99fy-core allows Stored XSS.This issue affects Free WooCommerce Theme 99fy Extension: from n/a through <= 1.2.8.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22802

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail yeemail allows Stored XSS.This issue affects Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail: from n/a through <= 2.1.4.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22803

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Advanced Product Information for WooCommerce woo-advanced-product-information allows Stored XSS.This issue affects Advanced Product Information for WooCommerce: from n/a through <= 1.1.4.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2025-22804

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.23.

    Published: 9 Jan 2025