Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-21 CVE-2024-37495 Cross-site Scripting vulnerability in Mediavine Create
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mediavine Create by Mediavine allows Stored XSS.This issue affects Create by Mediavine: from n/a through 1.9.7.
network
low complexity
mediavine CWE-79
5.4
2024-07-21 CVE-2024-37509 Cross-site Scripting vulnerability in Makecommerce for Woocommerce
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maksekeskus AS MakeCommerce for WooCommerce allows Reflected XSS.This issue affects MakeCommerce for WooCommerce: from n/a through 3.5.1.
network
low complexity
makecommerce CWE-79
6.1
2024-07-21 CVE-2024-37514 Cross-site Scripting vulnerability in Artistscope Copysafe web Protection
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArtistScope CopySafe Web Protection allows Stored XSS.This issue affects CopySafe Web Protection: from n/a through 3.14.
network
low complexity
artistscope CWE-79
5.4
2024-07-21 CVE-2024-37519 Cross-site Scripting vulnerability in Leap13 Premium Blocks for Gutenburg
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.27.
network
low complexity
leap13 CWE-79
5.4
2024-07-21 CVE-2024-37521 Cross-site Scripting vulnerability in ZWW Zbench
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in zwwooooo zBench allows Stored XSS.This issue affects zBench: from n/a through 1.4.2.
network
low complexity
zww CWE-79
5.4
2024-07-21 CVE-2024-37522 Cross-site Scripting vulnerability in Dcurasi CC & BCC for Woocommerce Order Emails
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dario Curasì CC & BCC for Woocommerce Order Emails allows Stored XSS.This issue affects CC & BCC for Woocommerce Order Emails: from n/a through 1.4.1.
network
low complexity
dcurasi CWE-79
4.8
2024-07-21 CVE-2024-38436 Cross-site Scripting vulnerability in Commugen SOX 365
Commugen SOX 365 – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
low complexity
commugen CWE-79
6.1
2024-07-21 CVE-2024-37523 Cross-site Scripting vulnerability in Amplifyplugins Login Logo Editor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AMP-MODE Login Logo Editor allows Stored XSS.This issue affects Login Logo Editor: from n/a through 1.3.3.
network
low complexity
amplifyplugins CWE-79
5.4
2024-07-21 CVE-2024-37536 Cross-site Scripting vulnerability in Web357 Easy Custom Code
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Web357 Easy Custom Code (LESS/CSS/JS) – Live editing allows Stored XSS.This issue affects Easy Custom Code (LESS/CSS/JS) – Live editing: from n/a through 1.0.8.
network
low complexity
web357 CWE-79
5.4
2024-07-21 CVE-2024-37537 Cross-site Scripting vulnerability in Uusweb WS Contact Form
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in UusWeb.Ee WS Contact Form allows Stored XSS.This issue affects WS Contact Form: from n/a through 1.3.7.
network
low complexity
uusweb CWE-79
5.4