CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-52465

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Mitigation, Inc. LGPD Framework lgpd-framework allows Reflected XSS.This issue affects LGPD Framework: from n/a through <= 2.0.2.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-52466

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Explara Explara Events explara-events allows Reflected XSS.This issue affects Explara Events: from n/a through <= 0.1.3.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-52467

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in August Infotech AI Responsive Gallery Album ai-responsive-gallery-album allows Reflected XSS.This issue affects AI Responsive Gallery Album: from n/a through <= 1.4.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-52468

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeadBoxer LeadBoxer leadboxer allows Reflected XSS.This issue affects LeadBoxer: from n/a through <= 1.3.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-52469

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dhrubok Infotech Services Ltd. WooCommerce Price Alert price-alert-woocommerce allows Reflected XSS.This issue affects WooCommerce Price Alert: from n/a through <= 1.0.4.

    Published: 2 Dec 2024
    10
    Critical

    CVE-2024-52476

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web Server.This issue affects Fediverse Embeds: from n/a through <= 1.5.3.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-52477

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in docxpresso Document & Data Automation document-data-automation allows Stored XSS.This issue affects Document & Data Automation: from n/a through <= 1.6.1.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-52478

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Jobify jobify allows Stored XSS.This issue affects Jobify: from n/a through < 4.3.0.

    Published: 2 Dec 2024
    4.3
    Medium

    CVE-2024-52479

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Astoundify Jobify jobify allows Cross Site Request Forgery.This issue affects Jobify: from n/a through < 4.3.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-52482

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafalautopilot Ortto autopilot allows Reflected XSS.This issue affects Ortto: from n/a through <= 1.0.19.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-52483

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Igor Benic LeanPress leanpress allows Reflected XSS.This issue affects LeanPress: from n/a through <= 1.0.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-52484

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in deepintowp Wc Recently viewed products wc-recently-viewed-products allows Reflected XSS.This issue affects Wc Recently viewed products: from n/a through <= 1.0.1.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-52486

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SolverWp Elementor Portfolio Builder portfolio-builder-elementor allows DOM-Based XSS.This issue affects Elementor Portfolio Builder: from n/a through <= 1.0.0.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-52487

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows Stored XSS.This issue affects Ultimate Classified Listings: from n/a through <= 1.7.

    Published: 2 Dec 2024
    5.9
    Medium

    CVE-2024-52489

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in udidol Add Chat App Button add-whatsapp-button allows Stored XSS.This issue affects Add Chat App Button: from n/a through <= 2.1.5.

    Published: 2 Dec 2024
    5.9
    Medium

    CVE-2024-52491

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sanil Shakya Sticky Social Icons sticky-social-icons allows Stored XSS.This issue affects Sticky Social Icons: from n/a through <= 1.2.1.

    Published: 2 Dec 2024
    5.9
    Medium

    CVE-2024-52492

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Image horizontal reel scroll slideshow image-horizontal-reel-scroll-slideshow allows Stored XSS.This issue affects Image horizontal reel scroll slideshow: from n/a through <= 13.4.

    Published: 2 Dec 2024
    5.9
    Medium

    CVE-2024-52493

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Leuze Meteor Slides meteor-slides allows Stored XSS.This issue affects Meteor Slides: from n/a through <= 1.5.7.

    Published: 2 Dec 2024
    5.9
    Medium

    CVE-2024-52494

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Varone, Tim Berneman Dynamic "To Top" allows Stored XSS.This issue affects Dynamic "To Top": from 3.5.2 through n/a.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-52502

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImbaSynergy ImbaChat imbachat-widget allows DOM-Based XSS.This issue affects ImbaChat: from n/a through <= 3.1.4.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-52503

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tailored Media Tailored Tools tailored-tools allows Stored XSS.This issue affects Tailored Tools: from n/a through <= 1.8.4.

    Published: 2 Dec 2024
    4.3
    Medium

    CVE-2024-53707

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ahmeti Ahmeti Wp Güzel Sözler ahmeti-wp-guzel-sozler allows Cross Site Request Forgery.This issue affects Ahmeti Wp Güzel Sözler: from n/a through <= 4.0.

    Published: 2 Dec 2024
    5.3
    Medium

    CVE-2024-53708

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI Quiz: from n/a through <= 1.1.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-53709

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generic Elements generic-elements-for-elementor allows DOM-Based XSS.This issue affects Generic Elements: from n/a through <= 1.2.5.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53710

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ITERAS ITERAS iteras allows Stored XSS.This issue affects ITERAS: from n/a through <= 1.8.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53711

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in tranchesdunet Hotlink2Watermark hotlink2watermark allows Stored XSS.This issue affects Hotlink2Watermark: from n/a through <= 0.3.2.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53712

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in kevmimcc Kevin's kevins-plugin allows Stored XSS.This issue affects Kevin's: from n/a through <= 2.0.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53713

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rickota Silverlight Video Player smooth-streaming-player allows Stored XSS.This issue affects Silverlight Video Player: from n/a through <= 1.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53714

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Continue Shopping From Cart continue-shopping-from-cart-page allows Stored XSS.This issue affects Continue Shopping From Cart: from n/a through <= 1.3.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53715

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Simple Travel Map simple-travel-map allows Stored XSS.This issue affects Simple Travel Map: from n/a through <= 0.1.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53716

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in overtrue wp auto top wp-auto-top allows Stored XSS.This issue affects wp auto top: from n/a through <= 2.9.3.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53717

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in yonisink yPHPlista yphplista allows Stored XSS.This issue affects yPHPlista: from n/a through <= 1.1.1.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53718

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Multi Feed Reader multi-feed-reader allows Stored XSS.This issue affects Multi Feed Reader: from n/a through <= 2.2.4.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53719

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in onigetoc Zajax – Ajax Navigation zajax-ajax-navigation allows Stored XSS.This issue affects Zajax – Ajax Navigation: from n/a through <= 0.4.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53720

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ole1986 WP-ISPConfig 3 wp-ispconfig3 allows Stored XSS.This issue affects WP-ISPConfig 3: from n/a through <= 1.5.6.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-53721

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stachethemes Advanced Event Manager advanced-event-manager allows Stored XSS.This issue affects Advanced Event Manager: from n/a through <= 1.1.6.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53722

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rockemmusic Favicon My Blog favicon-my-blog allows Stored XSS.This issue affects Favicon My Blog: from n/a through <= 1.0.2.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53723

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in acbaltaci Google Plus Share and +1 Button google-plus-share-and-plusone-button allows Stored XSS.This issue affects Google Plus Share and +1 Button: from n/a through <= 1.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53724

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ronnybull IceStats icestats allows Stored XSS.This issue affects IceStats: from n/a through <= 1.3.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53725

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in aMiT Post Hits Counter hits-counter allows Reflected XSS.This issue affects Post Hits Counter: from n/a through <= 2.8.23.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53726

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in RealtyCandy.com RealtyCandy IDX Broker Extended realtycandy-idx-broker-extended allows Stored XSS.This issue affects RealtyCandy IDX Broker Extended: from n/a through <= 1.5.1.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53727

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Lars Koudal LinkLaunder SEO linklaunder-seo-plugin allows Stored XSS.This issue affects LinkLaunder SEO: from n/a through <= 0.92.1.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53728

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Oliver Lindner Protect Your Content protect-your-content allows Stored XSS.This issue affects Protect Your Content: from n/a through <= 1.0.2.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53729

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in plumwd Blizzard Quotes blizzard-quotes allows Stored XSS.This issue affects Blizzard Quotes: from n/a through <= 1.3.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-53741

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simple Popup simple-popup-plugin allows DOM-Based XSS.This issue affects Simple Popup: from n/a through <= 4.6.

    Published: 2 Dec 2024
    5.4
    Medium

    CVE-2024-53751

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online build-app-online allows Cross Site Request Forgery.This issue affects Build App Online: from n/a through <= 1.0.23.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53753

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CultBooking CultBooking Hotel Booking Engine cultbooking-booking-engine allows Stored XSS.This issue affects CultBooking Hotel Booking Engine: from n/a through <= 2.1.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53754

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Out Of Stock Badge out-of-stock-badge allows Cross Site Request Forgery.This issue affects Out Of Stock Badge: from n/a through <= 2.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53755

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Andrea Pernici Third Party Cookie Eraser third-party-cookie-eraser allows Stored XSS.This issue affects Third Party Cookie Eraser: from n/a through <= 1.0.2.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53759

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Planet Studio ArCa Payment Gateway arca-payment-gateway allows Stored XSS.This issue affects ArCa Payment Gateway: from n/a through <= 1.3.1.

    Published: 2 Dec 2024