Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-27 CVE-2024-8991 Cross-site Scripting vulnerability in Hyumika Openstreetmap
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
hyumika CWE-79
5.4
2024-09-27 CVE-2024-9049 Cross-site Scripting vulnerability in Fastlinemedia Beaver Builder
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions up to, and including, 2.8.3.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
fastlinemedia CWE-79
5.4
2024-09-27 CVE-2024-7713 Cleartext Transmission of Sensitive Information vulnerability in Ays-Pro Chatgpt Assistant
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
network
low complexity
ays-pro CWE-319
7.5
2024-09-27 CVE-2024-7714 Unspecified vulnerability in Ays-Pro Chatgpt Assistant
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0.
network
low complexity
ays-pro
7.5
2024-09-27 CVE-2024-8922 Deserialization of Untrusted Data vulnerability in Piwebsolution Product Enquiry for Woocommerce
The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 via deserialization of untrusted input in enquiry_detail.php.
network
low complexity
piwebsolution CWE-502
8.8
2024-09-27 CVE-2024-8965 Cross-site Scripting vulnerability in Codesupply Absolute Reviews
The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping.
network
low complexity
codesupply CWE-79
5.4
2024-09-27 CVE-2024-9130 SQL Injection vulnerability in Givewp
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.16.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
givewp CWE-89
7.2
2024-09-26 CVE-2024-4099 Improper Encoding or Escaping of Output vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1.
network
low complexity
gitlab CWE-116
5.3
2024-09-26 CVE-2024-8974 Incorrect Authorization vulnerability in Gitlab
Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."
network
low complexity
gitlab CWE-863
4.3
2024-09-26 CVE-2024-46628 OS Command Injection vulnerability in Tendacn G3 Firmware 15.03.05.05
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
network
low complexity
tendacn CWE-78
critical
9.8