1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-12109
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-10009
Melapress File Monitor Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-10638
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-9689
Post From Frontend Web Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack

CVE-2024-9828
Taskbuilder Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks

CVE-2024-5473
Simple Photoswipe Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4755
Google CSE Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3628
EasyEvent Web Windows
3.8
LOW
EPSS
0.2%
2024 1 PoC

The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-2972
Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4145
Search & Replace Web Database Windows
3.8
LOW
EPSS
0.5%
2024 1 PoC

The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).

CVE-2024-3076
MM-email2image Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-13116
Crelly Slider Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5030
CM Table Of Contents Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2024-38829
Spring LDAP Web Windows
3.7
LOW
EPSS
0.1%
2024 CWE-178 1 PoC

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0. The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried Related to CVE-2024-38820 https://spring.io/security/cve-2024-38820

CVE-2024-7762
Simple Job Board Web Windows
3.7
LOW
EPSS
0.6%
2024 1 PoC

The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes

CVE-2024-7083
Email Encoder Web Windows
3.5
LOW
EPSS
0.0%
2024 1 PoC

The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13124
Photo Gallery by 10Web Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13125
Everest Forms Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4004
Advanced Cron Manager Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2220
Button contact VR Web Windows
3.5
LOW
EPSS
0.3%
2024 1 PoC

The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)