2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12873MEDIUM6.1The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back...
CVE-2024-12812HIGH7.5The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before...
CVE-2024-12808MEDIUM4.8The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before...
CVE-2024-12800MEDIUM4.8The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privile...
CVE-2024-12770MEDIUM4.8The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-12767LOW3.5The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view c...
CVE-2024-12750MEDIUM4.3The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which co...
CVE-2024-12743MEDIUM4.8The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-12739MEDIUM4.8The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allo...
CVE-2024-12735HIGH7.2The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL...
CVE-2024-12734MEDIUM6.1The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sani...
CVE-2024-12733MEDIUM6.1The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-12732MEDIUM6.1The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-12726MEDIUM6.1The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page,...
CVE-2024-12725MEDIUM6.1The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting...
CVE-2024-12724MEDIUM6.1The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in th...
CVE-2024-12722MEDIUM5.4The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of...
CVE-2024-12716MEDIUM4.8The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which ...
CVE-2024-12680MEDIUM4.8The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-12679MEDIUM4.8The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-12301MEDIUM6.5The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers...
CVE-2024-12282MEDIUM6.1The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as...
CVE-2024-11843MEDIUM4.8The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high p...
CVE-2024-11719MEDIUM6.1The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation ...
CVE-2024-11718MEDIUM5.4The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, whi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now