2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8617MEDIUM4.8The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high...
CVE-2024-8542MEDIUM4.8The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8493MEDIUM4.8The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-8492MEDIUM4.8The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-8426MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul...
CVE-2024-8398MEDIUM4.3The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, whi...
CVE-2024-8397MEDIUM5.4The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers whe...
CVE-2024-8286MEDIUM6.5The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which co...
CVE-2024-8284MEDIUM4.8The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow...
CVE-2024-8245MEDIUM4.3The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could a...
CVE-2024-8187MEDIUM4.8The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8095MEDIUM6.1The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well ...
CVE-2024-8094MEDIUM6.5The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could...
CVE-2024-8090MEDIUM6.1The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation a...
CVE-2024-8085MEDIUM6.1The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as we...
CVE-2024-8082MEDIUM4.3The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could...
CVE-2024-8050MEDIUM4.3The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, whic...
CVE-2024-8032MEDIUM6.1The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sani...
CVE-2024-8031MEDIUM6.5The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloade...
CVE-2024-8009MEDIUM4.3The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers ...
CVE-2024-7984MEDIUM4.3The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which...
CVE-2024-7769MEDIUM4.8The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-7761MEDIUM6.1In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you...
CVE-2024-7759MEDIUM4.8The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-7758MEDIUM4.8The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could all...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now