Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-01-22 CVE-2025-0604 A flaw was found in Keycloak.
network
low complexity
CWE-287
5.4
2025-01-22 CVE-2024-13447 Missing Authorization vulnerability in Thimpress WP Hotel Booking
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6.
network
low complexity
thimpress CWE-862
4.3
2025-01-22 CVE-2022-23439 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Fortinet products
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before version 7.0.4, FortiRecorder version 6.4.0 through 6.4.2 and before 6.0.10, FortiAuthenticator version 6.4.0 through 6.4.1 and before 6.3.3, FortiNDR version 7.2.0 before 7.1.0, FortiWLC before version 8.6.4, FortiPortal before version 6.0.9, FortiOS version 7.2.0 and before 7.0.5, FortiADC version 7.0.0 through 7.0.1 and before 6.2.3 , FortiDDoS before version 5.5.1, FortiDDoS-F before version 6.3.3, FortiTester before version 7.2.1, FortiSOAR before version 7.2.2 and FortiSwitch before version 6.3.3 allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
network
low complexity
fortinet CWE-610
6.1
2025-01-22 CVE-2024-13319 Cross-site Scripting vulnerability in Themify Builder
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5.
network
low complexity
themify CWE-79
6.1
2025-01-22 CVE-2024-13360 Server-Side Request Forgery (SSRF) vulnerability in Aipower
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector().
network
low complexity
aipower CWE-918
5.4
2025-01-22 CVE-2024-12117 Cross-site Scripting vulnerability in Gambit Stackable
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the Button block in all versions up to, and including, 3.13.11 due to insufficient input sanitization and output escaping.
network
low complexity
gambit CWE-79
5.4
2025-01-22 CVE-2024-13406 Cross-site Scripting vulnerability in Icopydoc XML for Google Merchant Center
The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and including, 3.0.11 due to insufficient input sanitization and output escaping.
network
low complexity
icopydoc CWE-79
6.1
2025-01-22 CVE-2024-12879 Missing Authorization vulnerability in Quantumcloud Wpot
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qc_wp_latest_update_check_pro' function in all versions up to, and including, 13.5.5.
network
low complexity
quantumcloud CWE-862
4.3
2025-01-22 CVE-2024-13584 Cross-site Scripting vulnerability in Videowhisper Picture Gallery
The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode in all versions up to, and including, 1.5.19 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
videowhisper CWE-79
5.4
2025-01-22 CVE-2024-13590 Cross-site Scripting vulnerability in Ayecode Ketchup Shortcodes
The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, and including, 0.1.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
ayecode CWE-79
5.4