Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-46934 Cross-site Scripting vulnerability in Rocket.Chat
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS).
network
low complexity
rocket-chat CWE-79
6.1
2024-09-25 CVE-2024-46935 Unspecified vulnerability in Rocket.Chat
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).
network
low complexity
rocket-chat
7.5
2024-09-25 CVE-2024-47048 Cross-site Scripting vulnerability in Rocket.Chat
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.
network
low complexity
rocket-chat CWE-79
5.4
2024-09-25 CVE-2024-7398 Cross-site Scripting vulnerability in Concretecms Concrete CMS
Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output.
network
low complexity
concretecms CWE-79
5.4
2024-09-25 CVE-2024-8103 Cross-site Scripting vulnerability in Gcsdesign WP Category Dropdown
The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping.
network
low complexity
gcsdesign CWE-79
5.4
2024-09-25 CVE-2024-8267 The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute within the 'wp:radio-player' Gutenberg block in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-09-25 CVE-2024-8291 Cross-site Scripting vulnerability in Concretecms Concrete CMS
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A rogue admin could add malicious code to the Thumbnails/Add-Type.
network
low complexity
concretecms CWE-79
4.8
2024-09-25 CVE-2024-8436 The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
CWE-89
critical
9.9
2024-09-25 CVE-2024-8437 The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5.
network
low complexity
CWE-862
4.3
2024-09-25 CVE-2024-8801 Unspecified vulnerability in Wedevs Happy Addons for Elementor
The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget.
network
low complexity
wedevs
4.3