Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-26 | CVE-2024-9125 | Cross-site Scripting vulnerability in Kingblack King IE The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9127 | Cross-site Scripting vulnerability in Codecabin Super Testimonials 3.0.0 The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9173 | Cross-site Scripting vulnerability in Alefypimentel GF Custom Style 2.0 The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9198 | Cross-site Scripting vulnerability in Clibomanager Clibo Manager 1.1.9.1 Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture. | 5.4 |
2024-09-26 | CVE-2024-9199 | Unspecified vulnerability in Clibomanager Clibo Manager 1.1.9.2 Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of service (DoS). | 7.5 |
2024-09-26 | CVE-2024-8872 | Cross-site Scripting vulnerability in Bizswoop Store Hours for Woocommerce The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.3.20. | 6.1 |
2024-09-26 | CVE-2024-9025 | Missing Authorization vulnerability in Codesupply Sight The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2. | 5.3 |
2024-09-26 | CVE-2024-42406 | Unspecified vulnerability in Mattermost Server Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. | 5.4 |
2024-09-26 | CVE-2024-45843 | Server-Side Request Forgery (SSRF) vulnerability in Mattermost Server Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba. | 5.4 |
2024-09-26 | CVE-2024-47003 | Unspecified vulnerability in Mattermost Server Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend. | 6.5 |