2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13823MEDIUM6.1The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-13730MEDIUM4.8The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which cou...
CVE-2024-13729MEDIUM4.8The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which co...
CVE-2024-13727MEDIUM6.1The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in th...
CVE-2024-13621MEDIUM4.8The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which cou...
CVE-2024-13619MEDIUM6.1The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13616MEDIUM4.8The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its setting...
CVE-2024-13486MEDIUM4.8The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-13482MEDIUM4.8The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-13384MEDIUM4.8The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some ...
CVE-2024-13383MEDIUM4.8The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-13382MEDIUM4.8The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could...
CVE-2024-13357MEDIUM4.8The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-13313MEDIUM4.8The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-13128MEDIUM4.8The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-13127MEDIUM4.8The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-13053MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ...
CVE-2024-12874MEDIUM4.8The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-12873MEDIUM6.1The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back...
CVE-2024-12808MEDIUM4.8The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before...
CVE-2024-12800MEDIUM4.8The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privile...
CVE-2024-12770MEDIUM4.8The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-12750MEDIUM4.3The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which co...
CVE-2024-12743MEDIUM4.8The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-12739MEDIUM4.8The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now