Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-03 CVE-2024-36113 Missing Authorization vulnerability in Discourse
Discourse is an open-source discussion platform.
network
low complexity
discourse CWE-862
6.5
2024-07-03 CVE-2024-39248 Cross-site Scripting vulnerability in Fikeulous Simpcms 0.1
A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field at /admin.php.
network
low complexity
fikeulous CWE-79
5.4
2024-07-03 CVE-2024-6052 Cross-site Scripting vulnerability in Checkmk
Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements
network
low complexity
checkmk CWE-79
5.4
2024-07-03 CVE-2024-36257 Unspecified vulnerability in Mattermost
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.
network
low complexity
mattermost
5.3
2024-07-03 CVE-2024-39361 Unspecified vulnerability in Mattermost
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID.
network
low complexity
mattermost
5.4
2024-07-03 CVE-2024-39807 Unspecified vulnerability in Mattermost
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
network
low complexity
mattermost
5.3
2024-07-03 CVE-2024-39830 Information Exposure Through Discrepancy vulnerability in Mattermost
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote cluster token comparison.
network
high complexity
mattermost CWE-203
5.9
2024-07-03 CVE-2024-6428 Unspecified vulnerability in Mattermost
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID.
network
low complexity
mattermost
6.5
2024-07-03 CVE-2024-4482 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied 'text_days' attribute.
network
low complexity
posimyth CWE-79
5.4
2024-07-03 CVE-2024-6263 Cross-site Scripting vulnerability in Syedbalkhi WP Lightbox 2
The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 due to insufficient input sanitization and output escaping.
network
low complexity
syedbalkhi CWE-79
5.4