Show filters
349 Total Results
Displaying 81-90 of 349
Sort by:
Attacker Value
Unknown

CVE-2024-32571

Disclosure Date: April 18, 2024 (last updated April 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 WP Stripe Checkout allows Stored XSS.This issue affects WP Stripe Checkout: from n/a through 1.2.2.41.
0
Attacker Value
Unknown

CVE-2024-3367

Disclosure Date: April 16, 2024 (last updated December 21, 2024)
Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc
Attacker Value
Unknown

CVE-2024-31262

Disclosure Date: April 12, 2024 (last updated April 13, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Jcodex WooCommerce Checkout Field Editor (Checkout Manager).This issue affects WooCommerce Checkout Field Editor (Checkout Manager): from n/a through 2.1.8.
0
Attacker Value
Unknown

CVE-2023-51672

Disclosure Date: April 11, 2024 (last updated April 11, 2024)
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
0
Attacker Value
Unknown

CVE-2024-2380

Disclosure Date: April 05, 2024 (last updated December 21, 2024)
Stored XSS in graph rendering in Checkmk <2.3.0b4.
Attacker Value
Unknown

CVE-2024-30518

Disclosure Date: March 29, 2024 (last updated January 05, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.
0
Attacker Value
Unknown

CVE-2024-24719

Disclosure Date: March 26, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.
0
Attacker Value
Unknown

CVE-2024-0866

Disclosure Date: March 26, 2024 (last updated April 02, 2024)
The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to execute needs to have a nonce check, and the nonce needs to be known to the attacker. Furthermore, the absence of a capability check is a requirement.
0
Attacker Value
Unknown

CVE-2024-1697

Disclosure Date: March 23, 2024 (last updated February 26, 2025)
The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the save_wcfe_options function in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-28824

Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.