Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-08 CVE-2024-6852 Cross-Site Request Forgery (CSRF) vulnerability in Ngothang WP Multitasking
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
network
low complexity
ngothang CWE-352
4.3
2024-09-08 CVE-2024-6853 Cross-Site Request Forgery (CSRF) vulnerability in Ngothang WP Multitasking
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack
network
low complexity
ngothang CWE-352
4.3
2024-09-08 CVE-2024-6855 Cross-Site Request Forgery (CSRF) vulnerability in Ngothang WP Multitasking
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack
network
low complexity
ngothang CWE-352
4.3
2024-09-08 CVE-2024-6856 Cross-Site Request Forgery (CSRF) vulnerability in Ngothang WP Multitasking
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
network
low complexity
ngothang CWE-352
4.3
2024-09-08 CVE-2024-6859 Cross-site Scripting vulnerability in Ngothang WP Multitasking
The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
network
low complexity
ngothang CWE-79
5.4
2024-09-08 CVE-2024-6925 Cross-Site Request Forgery (CSRF) vulnerability in Themetechmount Truebooker
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
network
low complexity
themetechmount CWE-352
4.3
2024-09-08 CVE-2024-8566 Cross-site Scripting vulnerability in Online Shop Store Project Online Shop Store 1.0
A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0.
network
low complexity
online-shop-store-project CWE-79
6.1
2024-09-07 CVE-2024-8563 Cross-site Scripting vulnerability in Rems PHP Crud 1.0
A vulnerability was found in SourceCodester PHP CRUD 1.0.
network
low complexity
rems CWE-79
6.1
2024-09-07 CVE-2024-8562 Cross-site Scripting vulnerability in Rems PHP Crud 1.0
A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic.
network
low complexity
rems CWE-79
6.1
2024-09-07 CVE-2024-8558 Improper Validation of Specified Quantity in Input vulnerability in Oretnom23 Food Ordering Management System 1.0
A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0.
network
low complexity
oretnom23 CWE-1284
4.3