2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6465MEDIUM4.3The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2024-6574MEDIUM5.3The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This ...
CVE-2024-6070MEDIUM4.8The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its setti...
CVE-2024-5744MEDIUM6.8The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it...
CVE-2024-5713MEDIUM5.4The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] pa...
CVE-2024-5644MEDIUM5.4The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-5627MEDIUM5.4The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with...
CVE-2024-5575MEDIUM4.7The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow h...
CVE-2024-5442MEDIUM5.9The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its setti...
CVE-2024-5286MEDIUM4.8The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-5284MEDIUM6.8The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-5283MEDIUM6.1The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-5282MEDIUM6.1The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-5281MEDIUM6.1The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-5280MEDIUM4.7The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-5079MEDIUM6.1The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, whi...
CVE-2024-5077MEDIUM6.8The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as we...
CVE-2024-5075MEDIUM5.9The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-5074MEDIUM5.4The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-5033MEDIUM5.9The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as ...
CVE-2024-5032MEDIUM4.7The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, ...
CVE-2024-5028MEDIUM6.5The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which...
CVE-2024-5002MEDIUM4.8The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which coul...
CVE-2024-4977MEDIUM6.8The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting i...
CVE-2024-4752MEDIUM5.9The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high pri...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now