CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2024-5280

    Last Modified: 19 May 2025

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack

    Published: 13 Jul 2024
    8.1
    High

    CVE-2024-5167

    Last Modified: 13 May 2025

    The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack

    Published: 13 Jul 2024
    7.1
    High

    CVE-2024-5151

    Last Modified: 13 May 2025

    The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 13 Jul 2024
    8.8
    High

    CVE-2024-5080

    Last Modified: 6 May 2025

    The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server

    Published: 13 Jul 2024
    6.1
    Medium

    CVE-2024-5079

    Last Modified: 6 May 2025

    The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks

    Published: 13 Jul 2024
    6.8
    Medium

    CVE-2024-5077

    Last Modified: 6 May 2025

    The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 13 Jul 2024
    8.8
    High

    CVE-2024-5076

    Last Modified: 6 May 2025

    The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 13 Jul 2024
    5.9
    Medium

    CVE-2024-5075

    Last Modified: 6 May 2025

    The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 13 Jul 2024
    5.4
    Medium

    CVE-2024-5074

    Last Modified: 2 May 2025

    The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 13 Jul 2024
    8.8
    High

    CVE-2024-5034

    Last Modified: 2 May 2025

    The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 13 Jul 2024
    5.9
    Medium

    CVE-2024-5033

    Last Modified: 2 May 2025

    The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 13 Jul 2024
    4.7
    Medium

    CVE-2024-5032

    Last Modified: 2 May 2025

    The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 13 Jul 2024
    6.5
    Medium

    CVE-2024-5028

    Last Modified: 13 May 2025

    The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 13 Jul 2024
    4.8
    Medium

    CVE-2024-5002

    Last Modified: 13 May 2025

    The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 13 Jul 2024
    6.8
    Medium

    CVE-2024-4977

    Last Modified: 13 Jun 2025

    The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 13 Jul 2024
    5.9
    Medium

    CVE-2024-4752

    Last Modified: 15 May 2025

    The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 13 Jul 2024
    5.4
    Medium

    CVE-2024-4602

    Last Modified: 15 May 2025

    The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 13 Jul 2024
    6.1
    Medium

    CVE-2024-4272

    Last Modified: 15 May 2025

    The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

    Published: 13 Jul 2024
    6.1
    Medium

    CVE-2024-4269

    Last Modified: 15 May 2025

    The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

    Published: 13 Jul 2024
    4.7
    Medium

    CVE-2024-4217

    Last Modified: 10 Jun 2025

    The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.

    Published: 13 Jul 2024
    5.9
    Medium

    CVE-2024-3964

    Last Modified: 13 May 2025

    The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 13 Jul 2024
    6.5
    Medium

    CVE-2024-3963

    Last Modified: 9 Jun 2025

    The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

    Published: 13 Jul 2024
    4.6
    Medium

    CVE-2024-3919

    Last Modified: 13 May 2025

    The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 13 Jul 2024
    5.9
    Medium

    CVE-2024-3753

    Last Modified: 13 May 2025

    The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 13 Jul 2024
    4.8
    Medium

    CVE-2024-3751

    Last Modified: 13 May 2025

    The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 13 Jul 2024
    6.8
    Medium

    CVE-2024-3710

    Last Modified: 13 May 2025

    The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

    Published: 13 Jul 2024
    6.8
    Medium

    CVE-2024-3632

    Last Modified: 15 May 2025

    The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 13 Jul 2024
    5.4
    Medium

    CVE-2024-3026

    Last Modified: 15 May 2025

    The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

    Published: 13 Jul 2024
    6.1
    Medium

    CVE-2024-2870

    Last Modified: 4 Jun 2025

    The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 13 Jul 2024
    5.3
    Medium

    CVE-2024-6574

    Last Modified: 15 Apr 2026

    The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This is due to the plugin not preventing direct access to several test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website. This plugin is no longer being maintained and has been closed for downloads.

    Published: 13 Jul 2024
    7.2
    High

    CVE-2024-5902

    Last Modified: 8 Apr 2026

    The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in feedback form responses that will execute whenever a high-privileged user tries to view them.

    Published: 12 Jul 2024
    —
    Unknown

    CVE-2024-6721

    Last Modified: 15 Jul 2024

    ** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-5324. Reason: This record is a reservation duplicate of CVE-2024-5324. Notes: All CVE users should reference CVE-2024-5324 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 12 Jul 2024
    3.1
    Low

    CVE-2023-41093

    Last Modified: 25 Sept 2025

    Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.

    Published: 12 Jul 2024
    5.4
    Medium

    CVE-2024-40690

    Last Modified: 21 Nov 2024

    IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 297720.

    Published: 12 Jul 2024
    6.5
    Medium

    CVE-2024-37405

    Last Modified: 15 Apr 2026

    Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.

    Published: 12 Jul 2024
    7.2
    High

    CVE-2024-39917

    Last Modified: 3 Nov 2025

    xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.

    Published: 12 Jul 2024
    9.1
    Critical

    CVE-2024-38736

    Last Modified: 15 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.

    Published: 12 Jul 2024
    7.5
    High

    CVE-2024-38735

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Event post event-post.This issue affects Event post: from n/a through <= 5.9.5.

    Published: 12 Jul 2024
    9.1
    Critical

    CVE-2024-38734

    Last Modified: 15 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4.

    Published: 12 Jul 2024
    7.1
    High

    CVE-2024-38717

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows PHP Local File Inclusion.This issue affects Booking Ultra Pro: from n/a through 1.1.13.

    Published: 12 Jul 2024
    6.5
    Medium

    CVE-2024-38716

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Calendar for Google allows PHP Local File Inclusion.This issue affects Events Calendar for Google: from n/a through 2.1.0.

    Published: 12 Jul 2024
    6.4
    Medium

    CVE-2024-39916

    Last Modified: 21 Nov 2024

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer that allows an attacker to modify files outside the export in the default installation. The exports have the no_subtree_check option. The no_subtree_check option means that if a client performs a file operation, the server will only check if the requested file is on the correct filesystem, not if it is in the correct directory. This enables modifying files in /images, accessing other files on the same filesystem, and accessing files on other filesystems. This vulnerability is fixed in 1.5.10.30.

    Published: 12 Jul 2024
    9.8
    Critical

    CVE-2024-39914

    Last Modified: 29 Sept 2025

    FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.

    Published: 12 Jul 2024
    6.5
    Medium

    CVE-2024-39909

    Last Modified: 15 Apr 2026

    KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems. A time/boolean SQL Injection is present in the following resource `/api/applicationResources` via the following parameter `packageID`. As it can be seen in backend/pkg/database/id_view.go, while building the SQL Query the `fmt.Sprintf` function is used to build the query string without the input having first been subjected to any validation. This vulnerability is fixed in 2.23.1.

    Published: 12 Jul 2024
    8.6
    High

    CVE-2024-39903

    Last Modified: 10 Apr 2025

    Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.

    Published: 12 Jul 2024
    6.5
    Medium

    CVE-2024-38715

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExS ExS Widgets allows PHP Local File Inclusion.This issue affects ExS Widgets: from n/a through 0.3.1.

    Published: 12 Jul 2024
    5.3
    Medium

    CVE-2024-38709

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating System allows PHP Local File Inclusion.This issue affects GD Rating System: from n/a through 3.6.

    Published: 12 Jul 2024
    6.5
    Medium

    CVE-2024-38706

    Last Modified: 28 Apr 2026

    Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.5.7.

    Published: 12 Jul 2024
    6.5
    Medium

    CVE-2024-38704

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress Team Manager allows PHP Local File Inclusion.This issue affects WordPress Team Manager: from n/a through 2.1.12.

    Published: 12 Jul 2024
    6.5
    Medium

    CVE-2024-38700

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in realmag777 WPCS allows Code Injection.This issue affects WPCS: from n/a through 1.2.0.3.

    Published: 12 Jul 2024