Export limit exceeded: 377282 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48153 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-13727 | 1 Memberspace | 1 Memberspace | 2025-06-10 | 6.1 Medium |
| The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users. | ||||
| CVE-2024-13823 | 1 Yofla | 1 360 Product Rotation | 2025-06-10 | 6.1 Medium |
| The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users. | ||||
| CVE-2024-13828 | 1 Danielpowney | 1 Badgearoo | 2025-06-10 | 6.1 Medium |
| The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | ||||
| CVE-2024-12770 | 1 Technowich | 1 Wp Ulike | 2025-06-10 | 4.8 Medium |
| The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-12800 | 1 Brijeshk89 | 1 Ip Based Login | 2025-06-10 | 4.8 Medium |
| The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-37262 | 1 Vcita | 1 Online Booking \& Scheduling Calendar | 2025-06-10 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.2. | ||||
| CVE-2023-39992 | 1 Vcita | 1 Online Booking \& Scheduling Calendar | 2025-06-10 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions. | ||||
| CVE-2024-12808 | 1 Wedevs | 1 Wp Erp | 2025-06-10 | 4.8 Medium |
| The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-13313 | 1 Aweber | 1 Aweber | 2025-06-10 | 4.8 Medium |
| The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-12743 | 1 Automattic | 1 Mailpoet | 2025-06-10 | 4.8 Medium |
| The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2023-22707 | 1 Wpsoul | 1 Greenshift | 2025-06-10 | 5.9 Medium |
| Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions. | ||||
| CVE-2024-45478 | 1 Apache | 1 Ranger | 2025-06-10 | 4.8 Medium |
| Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | ||||
| CVE-2024-3075 | 1 Mmilan81 | 1 Mm-email2image | 2025-06-10 | 8.1 High |
| The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2024-31783 | 1 Typora | 1 Typora | 2025-06-10 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation. | ||||
| CVE-2024-31013 | 1 Emlog | 1 Emlog | 2025-06-10 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter. | ||||
| CVE-2024-9021 | 2 Mikkosaari, Relevanssi | 2 Relevanssi, Relevanssi | 2025-06-09 | 5.4 Medium |
| In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor | ||||
| CVE-2024-12400 | 1 Goodlayers | 1 Tour Master | 2025-06-09 | 7.1 High |
| The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | ||||
| CVE-2024-12163 | 1 Goodlayers | 1 Goodlayers Core | 2025-06-09 | 6.5 Medium |
| The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads. | ||||
| CVE-2024-10510 | 2 Adbuddy Plus Wordpress, Netfunkdesign | 2 Adbuddy Plus Wordpress, Adbuddy\+ \(adblocker Detection\) | 2025-06-09 | 4.8 Medium |
| The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2023-6163 | 1 Themeum | 1 Wp Crowdfunding | 2025-06-09 | 4.8 Medium |
| The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||