Show filters
81 Total Results
Displaying 21-30 of 81
Sort by:
Attacker Value
Unknown
CVE-2023-47788
Disclosure Date: June 19, 2024 (last updated June 19, 2024)
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
0
Attacker Value
Unknown
CVE-2023-52199
Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Missing Authorization vulnerability in Matthias Pfefferle & Automattic ActivityPub.This issue affects ActivityPub: from n/a through 1.0.5.
0
Attacker Value
Unknown
CVE-2024-34766
Disclosure Date: June 03, 2024 (last updated June 04, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ChaosTheory allows Stored XSS.This issue affects ChaosTheory: from n/a through 1.3.
0
Attacker Value
Unknown
CVE-2024-4392
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-34549
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.2.2.
0
Attacker Value
Unknown
CVE-2023-47774
Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.
0
Attacker Value
Unknown
CVE-2023-52211
Disclosure Date: April 12, 2024 (last updated April 13, 2024)
Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.0.0.
0
Attacker Value
Unknown
CVE-2024-22155
Disclosure Date: April 07, 2024 (last updated April 10, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.
0
Attacker Value
Unknown
CVE-2023-51489
Disclosure Date: March 16, 2024 (last updated April 01, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
0
Attacker Value
Unknown
CVE-2023-50875
Disclosure Date: February 12, 2024 (last updated February 17, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.
0