Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-08 CVE-2024-35702 Cross-site Scripting vulnerability in Master-Addons Master Addons
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.6.0.
network
low complexity
master-addons CWE-79
5.4
2024-06-08 CVE-2024-35703 Cross-site Scripting vulnerability in Sinaextra Sina Extension for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through 3.5.3.
network
low complexity
sinaextra CWE-79
5.4
2024-06-08 CVE-2024-35704 Cross-site Scripting vulnerability in Wpblockart Blockart Blocks
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockArt BlockArt Blocks allows Stored XSS.This issue affects BlockArt Blocks: from n/a through 2.1.5.
network
low complexity
wpblockart CWE-79
5.4
2024-06-08 CVE-2024-35705 Cross-site Scripting vulnerability in Getbutterfly Block for Font Awesome
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ciprian Popescu Block for Font Awesome allows Stored XSS.This issue affects Block for Font Awesome: from n/a through 1.4.4.
network
low complexity
getbutterfly CWE-79
5.4
2024-06-08 CVE-2024-35706 Cross-site Scripting vulnerability in Heateor Social Login
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows Cross-Site Scripting (XSS).This issue affects Heateor Social Login: from n/a through 1.1.32.
network
low complexity
heateor CWE-79
6.1
2024-06-08 CVE-2024-35707 Cross-site Scripting vulnerability in Heateor Social Login
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows Stored XSS.This issue affects Heateor Social Login: from n/a through 1.1.32.
network
low complexity
heateor CWE-79
5.4
2024-06-08 CVE-2024-35708 Cross-site Scripting vulnerability in Apollo13Themes Rife Free
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in apollo13themes Rife Free allows Stored XSS.This issue affects Rife Free: from n/a through 2.4.19.
network
low complexity
apollo13themes CWE-79
5.4
2024-06-08 CVE-2024-35709 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.5.4.
network
low complexity
posimyth CWE-79
5.4
2024-06-08 CVE-2024-35711 Cross-site Scripting vulnerability in Themefreesia Event
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Freesia Event allows Stored XSS.This issue affects Event: from n/a through 1.2.2.
network
low complexity
themefreesia CWE-79
5.4
2024-06-08 CVE-2024-35713 Cross-site Scripting vulnerability in Uapp Testimonial Carousel for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in UAPP GROUP Testimonial Carousel For Elementor allows Stored XSS.This issue affects Testimonial Carousel For Elementor: from n/a through 10.1.1.
network
low complexity
uapp CWE-79
5.4