2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5282MEDIUM6.1The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-5281MEDIUM6.1The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-5280MEDIUM4.7The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-5167HIGH8.1The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or ...
CVE-2024-5151HIGH7.1The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2024-5080HIGH8.8The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload...
CVE-2024-5079MEDIUM6.1The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, whi...
CVE-2024-5077MEDIUM6.8The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as we...
CVE-2024-5076HIGH8.8The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to m...
CVE-2024-5075MEDIUM5.9The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-5074MEDIUM5.4The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-5034HIGH8.8The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make lo...
CVE-2024-5033MEDIUM5.9The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as ...
CVE-2024-5032MEDIUM4.7The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, ...
CVE-2024-5028MEDIUM6.5The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which...
CVE-2024-5002MEDIUM4.8The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which coul...
CVE-2024-4977MEDIUM6.8The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting i...
CVE-2024-4752MEDIUM5.9The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-4602MEDIUM5.4The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could ...
CVE-2024-4272MEDIUM6.1The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least th...
CVE-2024-4269MEDIUM6.1The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the ...
CVE-2024-4217MEDIUM4.7The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, mak...
CVE-2024-3964MEDIUM5.9The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, whi...
CVE-2024-3963MEDIUM6.5The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters,...
CVE-2024-3919MEDIUM4.6The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attribu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now