Page(s) : 1 ... 251 252 253 254 255 256 257 258 259 260 [261] 262 263 264 265 266 267 268 269 270 271 ... | Result(s) : 324700 |
Alerts
DATE | NAME | CATEGORIES | DETAIL | |
---|---|---|---|---|
N/A | 2025-05-15 | CVE-2024-13865 | cve | The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which co... |
N/A | 2025-05-15 | CVE-2024-1663 | cve | The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to pe... |
N/A | 2025-05-15 | CVE-2024-2643 | cve | The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its set... |
N/A | 2025-05-15 | CVE-2024-2869 | cve | The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Store... |
N/A | 2025-05-15 | CVE-2024-3062 | cve | The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to per... |
N/A | 2025-05-15 | CVE-2024-5026 | cve | The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C... |
N/A | 2025-05-15 | CVE-2024-5440 | cve | The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/pos... |
N/A | 2025-05-15 | CVE-2024-6159 | cve | The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX acti... |
N/A | 2025-05-15 | CVE-2024-6335 | cve | The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored... |
N/A | 2025-05-15 | CVE-2024-6462 | cve | The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros... |
N/A | 2025-05-15 | CVE-2024-6478 | cve | The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perfo... |
N/A | 2025-05-15 | CVE-2024-6486 | cve | The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authentica... |
N/A | 2025-05-15 | CVE-2024-6668 | cve | The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscrib... |
N/A | 2025-05-15 | CVE-2024-6690 | cve | The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites |
N/A | 2025-05-15 | CVE-2024-6693 | cve | The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Sc... |
N/A | 2025-05-15 | CVE-2024-6708 | cve | The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users ... |
N/A | 2025-05-15 | CVE-2024-6712 | cve | The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make lo... |
N/A | 2025-05-15 | CVE-2024-6713 | cve | The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross... |
5.4 | 2025-05-15 | CVE-2024-6718 | cve | The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is... |
N/A | 2025-05-15 | CVE-2024-6719 | cve | The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF a... |
Page(s) : 1 ... 251 252 253 254 255 256 257 258 259 260 [261] 262 263 264 265 266 267 268 269 270 271 ... | Result(s) : 324700 |