Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-07 CVE-2024-31878 Information Exposure Through Discrepancy vulnerability in IBM I
IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker.
network
low complexity
ibm CWE-203
5.3
2024-06-07 CVE-2024-37160 Cross-site Scripting vulnerability in Formwork Project Formwork
Formwork is a flat file-based Content Management System (CMS).
network
low complexity
formwork-project CWE-79
4.8
2024-06-07 CVE-2024-5382 Missing Authorization vulnerability in Master-Addons Master Addons
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ma-template' REST API route in all versions up to, and including, 2.0.6.1.
network
low complexity
master-addons CWE-862
5.3
2024-06-07 CVE-2024-5438 Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key.
network
low complexity
themeum CWE-639
4.3
2024-06-07 CVE-2024-5542 Cross-site Scripting vulnerability in Master-Addons Master Addons
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Navigation Menu widget of the plugin's Mega Menu extension in all versions up to, and including, 2.0.6.1 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
master-addons CWE-79
6.1
2024-06-07 CVE-2024-5426 Cross-site Scripting vulnerability in 10Web Photo Gallery
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping.
network
low complexity
10web CWE-79
5.4
2024-06-07 CVE-2024-5645 Cross-site Scripting vulnerability in Envothemes Envo Extra
The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter within the Button widget in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping.
network
low complexity
envothemes CWE-79
5.4
2024-06-07 CVE-2024-4703 Cross-site Scripting vulnerability in Horea Radu ONE Page Express Companion 1.6.37
The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_page_express_contact_form shortcode in all versions up to, and including, 1.6.37 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
horea-radu CWE-79
5.4
2024-06-07 CVE-2024-4451 Cross-site Scripting vulnerability in Extendthemes Colibri Page Builder
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
extendthemes CWE-79
5.4
2024-06-07 CVE-2024-4488 Cross-site Scripting vulnerability in Royal-Elementor-Addons Royal Elementor Addons
The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping.
network
low complexity
royal-elementor-addons CWE-79
5.4