Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-22 CVE-2024-37206 Cross-site Scripting vulnerability in Theme4Press Demo Awesome
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme4Press Demo Awesome allows Reflected XSS.This issue affects Demo Awesome: from n/a through 1.0.1.
network
low complexity
theme4press CWE-79
6.1
2024-07-22 CVE-2024-37211 Cross-site Scripting vulnerability in Ali2Woo Aliexpress Dropshipping With Alinext
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali2Woo Team Ali2Woo Lite allows Reflected XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5.
network
low complexity
ali2woo CWE-79
6.1
2024-07-22 CVE-2024-37215 Cross-site Scripting vulnerability in Creativeinteractivemedia Transition Slider
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeinteractivemedia Transition Slider – Responsive Image Slider and Gallery allows Stored XSS.This issue affects Transition Slider – Responsive Image Slider and Gallery: from n/a through 2.20.3.
network
low complexity
creativeinteractivemedia CWE-79
5.4
2024-07-22 CVE-2024-37216 Cross-site Scripting vulnerability in Generatewp Sketchfab Embed
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rami Yushuvaev Sketchfab Embed allows Stored XSS.This issue affects Sketchfab Embed: from n/a through 1.5.
network
low complexity
generatewp CWE-79
5.4
2024-07-22 CVE-2024-37217 Cross-site Scripting vulnerability in Prowcplugins Empty Cart Button for Woocommerce
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ProWCPlugins Empty Cart Button for WooCommerce allows Stored XSS.This issue affects Empty Cart Button for WooCommerce: from n/a through 1.3.8.
network
low complexity
prowcplugins CWE-79
5.4
2024-07-22 CVE-2024-37219 Cross-site Scripting vulnerability in Pagebuildersandwich Page Builder Sandwich
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PBN Hosting SL Page Builder Sandwich – Front-End Page Builder allows Stored XSS.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0.
network
low complexity
pagebuildersandwich CWE-79
5.4
2024-07-22 CVE-2024-37221 Cross-site Scripting vulnerability in Kimili Flash Embed
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Bester Kimili Flash Embed allows Stored XSS.This issue affects Kimili Flash Embed: from n/a through 2.5.3.
network
low complexity
kimili CWE-79
5.4
2024-07-22 CVE-2024-37223 Cross-site Scripting vulnerability in Nicdarkthemes Restaurant Food
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 2.0.
network
low complexity
nicdarkthemes CWE-79
5.4
2024-07-22 CVE-2024-37229 Cross-site Scripting vulnerability in Auburnforest Blogmentor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AuburnForest Blogmentor – Blog Layouts for Elementor allows Stored XSS.This issue affects Blogmentor – Blog Layouts for Elementor: from n/a through 1.5.
network
low complexity
auburnforest CWE-79
5.4
2024-07-22 CVE-2024-37239 Cross-site Scripting vulnerability in Wpmudev Branda
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Branda allows Stored XSS.This issue affects Branda: from n/a through 3.4.17.
network
low complexity
wpmudev CWE-79
4.8