Show filters
53 Total Results
Displaying 1-10 of 53
Sort by:
Attacker Value
Unknown

CVE-2024-13651

Disclosure Date: February 01, 2025 (last updated February 23, 2025)
The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_deactivate() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset some of the plugin's settings.
Attacker Value
Unknown

CVE-2024-52393

Disclosure Date: November 14, 2024 (last updated November 15, 2024)
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.15.
0
Attacker Value
Unknown

CVE-2024-43984

Disclosure Date: October 31, 2024 (last updated October 31, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
0
Attacker Value
Unknown

CVE-2024-43983

Disclosure Date: September 18, 2024 (last updated September 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Stored XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
Attacker Value
Unknown

CVE-2024-37270

Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a before 1.1.1.
0
Attacker Value
Unknown

CVE-2024-32143

Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0.
0
Attacker Value
Unknown

CVE-2024-35710

Disclosure Date: June 08, 2024 (last updated June 09, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Podlove Podlove Web Player.This issue affects Podlove Web Player: from n/a through 5.7.3.
0
Attacker Value
Unknown

CVE-2024-33952

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Unique allows Stored XSS.This issue affects Unique: from n/a through 0.3.0.
0
Attacker Value
Unknown

CVE-2024-32712

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.
0
Attacker Value
Unknown

CVE-2024-32812

Disclosure Date: April 24, 2024 (last updated April 24, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.11.
0