Categoria: CVE

CVE-2024-11452 | Chamber Dashboard Business Directory Plugin up to 3.3.8 on WordPress cross site scripting

A vulnerability has been found in Chamber Dashboard Business Directory Plugin up to 3.3.8 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Chamber Dashboard. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2024-11452. The attack can be launched remotely. There is no exploit...

Per saperne di più

CVE-2024-10789 | WP User Profile Avatar up to 1.0.5 on WordPress Setting cross-site request forgery

A vulnerability, which was classified as problematic, was found in WP User Profile Avatar up to 1.0.5 on WordPress. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross-site request forgery. This vulnerability is traded as CVE-2024-10789. It is possible to launch the attack remotely. There is no exploit...

Per saperne di più

CVE-2025-0502 | Crafter CMS up to 4.0.7/4.1.5 transmission of private resources into a new sphere (‘resource leak’)

A vulnerability, which was classified as problematic, has been found in Crafter CMS up to 4.0.7/4.1.5. This issue affects some unknown processing. The manipulation leads to transmission of private resources into a new sphere (‘resource leak’). The identification of this vulnerability is CVE-2025-0502. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2025-22795 | Thorsten Krug Multilang Contact Form Plugin up to 1.5 on WordPress cross site scripting

A vulnerability classified as problematic has been found in Thorsten Krug Multilang Contact Form Plugin up to 1.5 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2025-22795. It is possible to initiate the attack remotely. There is no exploit...

Per saperne di più

CVE-2024-52783 | Xinje XDPPro up to 3.7.17c XNetSocketClient XDPPro.exe permission

A vulnerability was found in Xinje XDPPro up to 3.7.17c. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file XDPPro.exe of the component XNetSocketClient. The manipulation leads to permission issues. This vulnerability is known as CVE-2024-52783. The attack needs to be done within the local network. There is no exploit...

Per saperne di più

CVE-2025-22784 | Johan Ström Background Control Plugin up to 1.0.5 on WordPress cross-site request forgery

A vulnerability was found in Johan Ström Background Control Plugin up to 1.0.5 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. This vulnerability is traded as CVE-2025-22784. It is possible to launch the attack remotely. There is no exploit...

Per saperne di più

CVE-2025-22797 | Oğulcan Özügenç Gallery and Lightbox Plugin up to 1.0.14 on WordPress cross site scripting

A vulnerability has been found in Oğulcan Özügenç Gallery and Lightbox Plugin up to 1.0.14 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability was named CVE-2025-22797. The attack can be initiated remotely. There is no exploit...

Per saperne di più
Caricamento