2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8426MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul...
CVE-2024-8398MEDIUM4.3The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, whi...
CVE-2024-8397MEDIUM5.4The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers whe...
CVE-2024-8286MEDIUM6.5The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which co...
CVE-2024-8284MEDIUM4.8The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow...
CVE-2024-8245MEDIUM4.3The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could a...
CVE-2024-8187MEDIUM4.8The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-8095MEDIUM6.1The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well ...
CVE-2024-8094MEDIUM6.5The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could...
CVE-2024-8090MEDIUM6.1The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation a...
CVE-2024-8085MEDIUM6.1The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as we...
CVE-2024-8082MEDIUM4.3The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could...
CVE-2024-8050MEDIUM4.3The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, whic...
CVE-2024-8032MEDIUM6.1The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sani...
CVE-2024-8031MEDIUM6.5The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloade...
CVE-2024-8009MEDIUM4.3The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers ...
CVE-2024-7984MEDIUM4.3The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which...
CVE-2024-7769MEDIUM4.8The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-7762LOW3.7The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthen...
CVE-2024-7761MEDIUM6.1In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you...
CVE-2024-7759MEDIUM4.8The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-7758MEDIUM4.8The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could all...
CVE-2024-7556MEDIUM4.8The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-6809CRITICAL9.8The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using ...
CVE-2024-6798MEDIUM4.8The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow hi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now