Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-28 CVE-2024-50440 Cross-site Scripting vulnerability in Codepen
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Chris Coyier CodePen Embedded Pens Shortcode allows Stored XSS.This issue affects CodePen Embedded Pens Shortcode: from n/a through 1.0.2.
network
low complexity
codepen CWE-79
5.4
2024-10-28 CVE-2024-50441 Cross-site Scripting vulnerability in Cozythemes Cozy Blocks
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS.This issue affects Cozy Blocks: from n/a through 2.0.15.
network
low complexity
cozythemes CWE-79
5.4
2024-10-28 CVE-2024-50445 Cross-site Scripting vulnerability in Merkulove Selection Lite
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Merkulove Selection Lite allows Stored XSS.This issue affects Selection Lite: from n/a through 1.13.
network
low complexity
merkulove CWE-79
5.4
2024-10-28 CVE-2024-50446 Cross-site Scripting vulnerability in Futuriowp Futurio Extra
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FuturioWP Futurio Extra allows Stored XSS.This issue affects Futurio Extra: from n/a through 2.0.11.
network
low complexity
futuriowp CWE-79
5.4
2024-10-28 CVE-2024-50447 Cross-site Scripting vulnerability in Envothemes Envo'S Elementor Templates & Widgets for Woocommerce
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates & Widgets for WooCommerce: from n/a through 1.4.19.
network
low complexity
envothemes CWE-79
5.4
2024-10-28 CVE-2024-50448 Cross-site Scripting vulnerability in Yithemes Yith Woocommerce Product Add-Ons
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Reflected XSS.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.14.1.
network
low complexity
yithemes CWE-79
6.1
2024-10-28 CVE-2024-50449 Cross-site Scripting vulnerability in Redefiningtheweb PDF Generator Addon for Elementor Page Builder
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder allows Stored XSS.This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through 1.7.4.
network
low complexity
redefiningtheweb CWE-79
5.4
2024-10-28 CVE-2024-50451 Cross-site Scripting vulnerability in Pluginus Meta Data and Taxonomies Filter
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.
network
low complexity
pluginus CWE-79
5.4
2024-10-28 CVE-2024-50458 Cross-site Scripting vulnerability in Wpcodeus Advanced Sermons
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Stored XSS.This issue affects Advanced Sermons: from n/a through 3.4.
network
low complexity
wpcodeus CWE-79
5.4
2024-10-28 CVE-2024-50460 Cross-site Scripting vulnerability in Firelightwp Firelight Lightbox
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FirelightWP Firelight Lightbox allows Stored XSS.This issue affects Firelight Lightbox: from n/a through 2.3.3.
network
low complexity
firelightwp CWE-79
4.8