Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-18 CVE-2024-43324 Cross-site Scripting vulnerability in Cleversoft Clever Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons for Elementor: from n/a through 2.2.0.
network
low complexity
cleversoft CWE-79
4.8
2024-08-18 CVE-2024-43327 Cross-site Scripting vulnerability in Teleogistic Invite Anyone
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7.
network
low complexity
teleogistic CWE-79
6.1
2024-08-18 CVE-2024-43329 Cross-site Scripting vulnerability in Cpothemes Allegiant
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Chill Allegiant allegiant allows Stored XSS.This issue affects Allegiant: from n/a through 1.2.7.
network
low complexity
cpothemes CWE-79
5.4
2024-08-18 CVE-2024-43330 Cross-site Scripting vulnerability in Wpbeaveraddons Powerpack Lite for Beaver Builder
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack for Beaver Builder allows Reflected XSS.This issue affects PowerPack for Beaver Builder: from n/a before 2.37.4.
network
low complexity
wpbeaveraddons CWE-79
6.1
2024-08-18 CVE-2024-43335 Cross-site Scripting vulnerability in Cyberchimps Responsive Blocks
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: from n/a through 1.8.8.
network
low complexity
cyberchimps CWE-79
5.4
2024-08-18 CVE-2024-43342 Cross-site Scripting vulnerability in Bdthemes Ultimate Store KIT
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 1.6.4.
network
low complexity
bdthemes CWE-79
5.4
2024-08-17 CVE-2024-7902 Open Redirect vulnerability in Public Knowledge Project Open Journal Systems
A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic.
network
low complexity
public-knowledge-project CWE-601
6.1
2024-08-17 CVE-2024-7901 Cross-site Scripting vulnerability in Scada-Lts 2.7.8
A vulnerability has been found in Scada-LTS 2.7.8 and classified as problematic.
network
low complexity
scada-lts CWE-79
5.4
2024-08-17 CVE-2024-7900 Cross-site Scripting vulnerability in Tpmecms 1.3.3.2
A vulnerability, which was classified as problematic, was found in xiaohe4966 TpMeCMS 1.3.3.2.
network
low complexity
tpmecms CWE-79
4.8
2024-08-17 CVE-2024-7703 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.37 due to insufficient input sanitization and output escaping.
network
low complexity
6.4