2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6708MEDIUM4.8The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting ...
CVE-2024-6693MEDIUM4.8The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-6690MEDIUM6.1The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirectio...
CVE-2024-6668MEDIUM5.4The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access control...
CVE-2024-6667MEDIUM6.1The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outpu...
CVE-2024-6665MEDIUM4.8The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, wh...
CVE-2024-6478MEDIUM4.8The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, whic...
CVE-2024-6462MEDIUM4.8The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-6335MEDIUM4.8The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could a...
CVE-2024-5440MEDIUM5.4The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its short...
CVE-2024-5026MEDIUM4.8The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could all...
CVE-2024-4665MEDIUM6.4The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing use...
CVE-2024-3901MEDIUM6.8The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blo...
CVE-2024-3062MEDIUM4.8The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, wh...
CVE-2024-2869MEDIUM4.8The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could ...
CVE-2024-2643MEDIUM4.8The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin ...
CVE-2024-1663MEDIUM4.8The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, w...
CVE-2024-13865MEDIUM6.1The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13828MEDIUM6.1The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-13823MEDIUM6.1The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-13730MEDIUM4.8The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which cou...
CVE-2024-13729MEDIUM4.8The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which co...
CVE-2024-13727MEDIUM6.1The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in th...
CVE-2024-13621MEDIUM4.8The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which cou...
CVE-2024-13619MEDIUM6.1The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now