2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12633HIGH7.1The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross...
CVE-2024-12535HIGH8.6The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check wh...
CVE-2024-12471HIGH8.8The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is...
CVE-2024-12464MEDIUM6.4The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' sho...
CVE-2024-12440MEDIUM6.4The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in ...
CVE-2024-12439MEDIUM6.4The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' s...
CVE-2024-12438MEDIUM6.1The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross...
CVE-2024-12384MEDIUM6.1The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter...
CVE-2024-12383MEDIUM6.1The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-12261MEDIUM6.1The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' par...
CVE-2024-12073MEDIUM5.4The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter ...
CVE-2024-11887MEDIUM6.4The Geo Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'geotargetlygeoconten...
CVE-2024-11756MEDIUM6.4The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2024-11749MEDIUM6.4The App Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appizy' shortcode in a...
CVE-2024-11606MEDIUM5.3The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before o...
CVE-2024-11369MEDIUM6.1The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t...
CVE-2024-10562LOW2.7The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could ...
CVE-2024-10536MEDIUM4.3The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for Word...
CVE-2024-10102LOW2.7The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some ...
CVE-2024-9208MEDIUM6.1The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer...
CVE-2024-12470CRITICAL9.8The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to...
CVE-2024-12462MEDIUM6.4The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shor...
CVE-2024-12457MEDIUM6.4The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is ...
CVE-2024-12453MEDIUM6.4The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd...
CVE-2024-12445MEDIUM6.4The RightMessage WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rm_area' shortco...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now