2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12406MEDIUM6.5The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2024-12162MEDIUM6.1The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t...
CVE-2024-12156MEDIUM6.1The AI Content Writer, RSS Feed to Post, Autoblogging SEO Help plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2024-11891MEDIUM6.4The Perfect Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-11875MEDIUM6.4The Add infos to the events calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-11804MEDIUM6.1The Planaday API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all ver...
CVE-2024-11750MEDIUM6.4The ONLYOFFICE DocSpace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice-d...
CVE-2024-11723MEDIUM6.1The kvCORE IDX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter on pages with the ...
CVE-2024-11709MEDIUM4.3The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2024-11459MEDIUM6.1The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all v...
CVE-2024-11410MEDIUM6.4The Top and footer bars for announcements, notifications, advertisements, promotions – YooBar plugin for WordPress is vu...
CVE-2024-11384MEDIUM5.4The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-10910HIGH7.3The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_p...
CVE-2024-10590HIGH8.8The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2024-10182MEDIUM6.4The Cognito Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versio...
CVE-2024-12461MEDIUM6.4The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_asyn...
CVE-2024-12341MEDIUM4.3The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2024-12338MEDIUM6.1The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolb...
CVE-2024-12260MEDIUM6.1The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page'...
CVE-2024-12258MEDIUM6.1The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...
CVE-2024-11914MEDIUM6.4The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-11901MEDIUM6.4The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POW...
CVE-2024-11689HIGH8.8The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-11683MEDIUM6.1The Newsletter Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'token_type' p...
CVE-2024-11443HIGH8.8The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now