CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-32440

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.8.0.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-32441

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.7.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-32442

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.7.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-32443

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2.

    Published: 15 Apr 2024
    5.4
    Medium

    CVE-2024-32445

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition.This issue affects WebinarIgnition: from n/a through <= 3.05.8.

    Published: 15 Apr 2024
    5.4
    Medium

    CVE-2024-32446

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce.This issue affects Wallet System for WooCommerce: from n/a through 2.5.9.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-32447

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.

    Published: 15 Apr 2024
    9.8
    Critical

    CVE-2024-3701

    Last Modified: 17 Jun 2025

    The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-32448

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in VideoYield.Com Ads.Txt Admin.This issue affects Ads.Txt Admin: from n/a through 1.3.

    Published: 15 Apr 2024
    5.4
    Medium

    CVE-2024-32449

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in MagniGenie RestroPress.This issue affects RestroPress: from n/a through 3.1.2.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-32450

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a through 1.6.0.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-32451

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.4.2.

    Published: 15 Apr 2024
    5.4
    Medium

    CVE-2024-32452

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.

    Published: 15 Apr 2024
    7.1
    High

    CVE-2024-30545

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nick Powers Social Author Bio allows Stored XSS.This issue affects Social Author Bio: from n/a through 2.4.

    Published: 15 Apr 2024
    7.1
    High

    CVE-2024-31086

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Change default login logo,url and title allows Cross-Site Scripting (XSS).This issue affects Change default login logo,url and title: from n/a through 2.0.

    Published: 15 Apr 2024
    7.1
    High

    CVE-2024-31093

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kaloyan K. Tsvetkov Broken Images allows Cross-Site Scripting (XSS).This issue affects Broken Images: from n/a through 0.2.

    Published: 15 Apr 2024
    7.1
    High

    CVE-2024-32082

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site allows Cross Site Request Forgery.This issue affects Sync Post With Other Site: from n/a through <= 1.9.1.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-3505

    Last Modified: 1 Apr 2025

    JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.

    Published: 15 Apr 2024
    7.6
    High

    CVE-2024-32087

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExportFeed.Com Product Feed on WooCommerce for Google.This issue affects Product Feed on WooCommerce for Google: from n/a through 3.5.7.

    Published: 15 Apr 2024
    7.6
    High

    CVE-2024-32098

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter.This issue affects Advanced Page Visit Counter: from n/a through 8.0.6.

    Published: 15 Apr 2024
    8.5
    High

    CVE-2024-32125

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.

    Published: 15 Apr 2024
    8.5
    High

    CVE-2024-32127

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Markus Seyer Find Duplicates.This issue affects Find Duplicates: from n/a through 1.4.6.

    Published: 15 Apr 2024
    9.3
    Critical

    CVE-2024-32128

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4.

    Published: 15 Apr 2024
    7.6
    High

    CVE-2024-32132

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codeboxr Team CBX Bookmark & Favorite.This issue affects CBX Bookmark & Favorite: from n/a through 1.7.20.

    Published: 15 Apr 2024
    7.6
    High

    CVE-2024-32134

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nasirahmed Forms to Zapier, Integromat, IFTTT, Workato, Automate.Io, elastic.Io, Built.Io, APIANT, Webhook.This issue affects Forms to Zapier, Integromat, IFTTT, Workato, Automate.Io, elastic.Io, Built.Io, APIANT, Webhook: from n/a through 1.1.12.

    Published: 15 Apr 2024
    7.6
    High

    CVE-2024-32135

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPZest Disable Comments | WPZest.This issue affects Disable Comments | WPZest: from n/a through 1.51.

    Published: 15 Apr 2024
    7.6
    High

    CVE-2024-32136

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xenioushk BWL Advanced FAQ Manager.This issue affects BWL Advanced FAQ Manager: from n/a through 2.0.3.

    Published: 15 Apr 2024
    8.5
    High

    CVE-2024-32137

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin User Activity Log Pro.This issue affects User Activity Log Pro: from n/a through 2.3.4.

    Published: 15 Apr 2024
    8.5
    High

    CVE-2024-32139

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12.

    Published: 15 Apr 2024
    4.4
    Medium

    CVE-2024-32431

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2.

    Published: 15 Apr 2024
    4.4
    Medium

    CVE-2024-32430

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14.

    Published: 15 Apr 2024
    4.4
    Medium

    CVE-2024-32454

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wappointment.This issue affects Appointment Bookings for Zoom GoogleMeet and more – Wappointment: from n/a through 2.6.0.

    Published: 15 Apr 2024
    5.5
    Medium

    CVE-2023-52144

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Product Feed Manager: from n/a through 7.3.15.

    Published: 15 Apr 2024
    6.5
    Medium

    CVE-2024-32079

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2024.2.

    Published: 15 Apr 2024
    7.1
    High

    CVE-2024-32133

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenies EZ Form Calculator allows Reflected XSS.This issue affects EZ Form Calculator: from n/a through 2.14.0.3.

    Published: 15 Apr 2024
    7.1
    High

    CVE-2024-32138

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Short URL allows Reflected XSS.This issue affects Short URL: from n/a through 1.6.8.

    Published: 15 Apr 2024
    6.5
    Medium

    CVE-2024-32140

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in libsyn Libsyn Publisher Hub libsyn-podcasting.This issue affects Libsyn Publisher Hub: from n/a through <= 1.4.4.

    Published: 15 Apr 2024
    7.1
    High

    CVE-2024-32145

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google Analytics Events allows Reflected XSS.This issue affects WP Google Analytics Events: from n/a through 2.8.0.

    Published: 15 Apr 2024
    6.5
    Medium

    CVE-2024-32147

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team - GhozyLab Easy Contact Form Lite allows Stored XSS.This issue affects Easy Contact Form Lite : from n/a through 1.1.23.

    Published: 15 Apr 2024
    7.1
    High

    CVE-2024-32149

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for WordPress allows Reflected XSS.This issue affects Jobs for WordPress: from n/a through 2.7.5.

    Published: 15 Apr 2024
    5.9
    Medium

    CVE-2024-32428

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moss Web Works MWW Disclaimer Buttons allows Stored XSS.This issue affects MWW Disclaimer Buttons: from n/a through 3.0.2.

    Published: 15 Apr 2024
    5.9
    Medium

    CVE-2024-32429

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Footer Credit allows Stored XSS.This issue affects Remove Footer Credit: from n/a through 1.0.13.

    Published: 15 Apr 2024
    5.9
    Medium

    CVE-2024-32453

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POEditor allows Stored XSS.This issue affects POEditor: from n/a through 0.9.8.

    Published: 15 Apr 2024
    6.3
    Medium

    CVE-2024-3771

    Last Modified: 12 Jul 2025

    A vulnerability was found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this issue is some unknown functionality of the file /edit-subject.php. The manipulation of the argument sub1/sub2/sub3/sub4/udate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-260618 is the identifier assigned to this vulnerability.

    Published: 15 Apr 2024
    6.3
    Medium

    CVE-2024-3770

    Last Modified: 12 Jul 2025

    A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage-courses.php?del=1. The manipulation of the argument del leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260617 was assigned to this vulnerability.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-2858

    Last Modified: 8 May 2025

    The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 15 Apr 2024
    6.1
    Medium

    CVE-2024-2857

    Last Modified: 8 May 2025

    The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-2836

    Last Modified: 8 May 2025

    The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 15 Apr 2024
    8.7
    High

    CVE-2024-2739

    Last Modified: 8 May 2025

    The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 15 Apr 2024
    6.5
    Medium

    CVE-2023-7201

    Last Modified: 8 May 2025

    The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

    Published: 15 Apr 2024