Show filters
891 Total Results
Displaying 111-120 of 891
Sort by:
Attacker Value
Unknown
CVE-2024-32945
Disclosure Date: July 15, 2024 (last updated July 17, 2024)
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
0
Attacker Value
Unknown
CVE-2024-2430
Disclosure Date: July 12, 2024 (last updated July 25, 2024)
The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2024-37115
Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown
CVE-2024-37424
Disclosure Date: July 09, 2024 (last updated July 09, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown
CVE-2024-35777
Disclosure Date: July 09, 2024 (last updated July 09, 2024)
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a through 8.9.2.
0
Attacker Value
Unknown
CVE-2024-37474
Disclosure Date: July 04, 2024 (last updated August 01, 2024)
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.
0
Attacker Value
Unknown
CVE-2024-37476
Disclosure Date: July 04, 2024 (last updated November 02, 2024)
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1.
0
Attacker Value
Unknown
CVE-2024-6428
Disclosure Date: July 03, 2024 (last updated July 06, 2024)
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working.
0
Attacker Value
Unknown
CVE-2024-39830
Disclosure Date: July 03, 2024 (last updated July 06, 2024)
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote cluster token comparison.
0
Attacker Value
Unknown
CVE-2024-39807
Disclosure Date: July 03, 2024 (last updated July 06, 2024)
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
0