2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12384MEDIUM6.1The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter...
CVE-2024-12383MEDIUM6.1The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-12261MEDIUM6.1The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' par...
CVE-2024-12073MEDIUM5.4The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter ...
CVE-2024-11887MEDIUM6.4The Geo Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'geotargetlygeoconten...
CVE-2024-11756MEDIUM6.4The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2024-11749MEDIUM6.4The App Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appizy' shortcode in a...
CVE-2024-11606MEDIUM5.3The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before o...
CVE-2024-11369MEDIUM6.1The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t...
CVE-2024-10562LOW2.7The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could ...
CVE-2024-10536MEDIUM4.3The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for Word...
CVE-2024-10102LOW2.7The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some ...
CVE-2024-9208MEDIUM6.1The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer...
CVE-2024-12470CRITICAL9.8The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to...
CVE-2024-12462MEDIUM6.4The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shor...
CVE-2024-12457MEDIUM6.4The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is ...
CVE-2024-12453MEDIUM6.4The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd...
CVE-2024-12445MEDIUM6.4The RightMessage WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rm_area' shortco...
CVE-2024-12435MEDIUM6.1The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_fea...
CVE-2024-12332MEDIUM6.5The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter...
CVE-2024-12327MEDIUM4.3The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-12324MEDIUM6.1The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in a...
CVE-2024-12322HIGH8.8The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2024-12313HIGH8.1The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, a...
CVE-2024-12291MEDIUM6.1The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now