CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 16, 2025

WordPress Add Custom Google Tag Manager Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress plugin 'Add Custom Google Tag Manager' versions through 1.0.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress WP Lyrics Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP Lyrics plugin, specifically in versions through 0.4.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.

2.0
Jan 16, 2025

WordPress MyAnime Widget Privilege Escalation Vulnerability via Cross-Site Request Forgery

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress MyAnime Widget plugin, affecting versions through 1.0, allows for privilege escalation. This vulnerability could enable attackers to manipulate users with higher privileges into performing actions they did not intend to.

2.1
Jan 16, 2025

WordPress Custom Post Type Lockdown Cross-Site Request Forgery Vulnerability Allowing Privilege Escalation

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Custom Post Type Lockdown plugin, specifically in versions through 1.11. This vulnerability allows for privilege escalation by enabling attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 16, 2025

WordPress DD Roles Plugin Privilege Escalation Vulnerability

A privilege escalation vulnerability has been identified in the WordPress DD Roles plugin, affecting versions through 4.1. This vulnerability allows users with low privileges to gain higher privileges, potentially leading to full control of the website.

1.8
Jan 16, 2025

Sanjaysolutions Loginplus Missing Authorization Vulnerability Allowing Broken Access Control

A broken access control vulnerability has been identified in the Sanjaysolutions Loginplus WordPress plugin, affecting versions through 1.2. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions or data exposure.

2.5
Jan 16, 2025

Joshua Wieczorek Bible Embed Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Joshua Wieczorek Bible Embed WordPress plugin, affecting versions through 0.0.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

WordPress WP-BlackCheck Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP-BlackCheck plugin, specifically in versions through 2.7.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

Zaantar WordPress Logging Service Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Zaantar WordPress Logging Service plugin, affecting versions through 1.5.4. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

WordPress Extra Options – Favicons Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Extra Options – Favicons plugin, affecting versions through 1.1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts into the site.

2.0
Jan 16, 2025

SpruceJoy Cookie Consent & Autoblock for GDPR/CCPA Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the SpruceJoy Cookie Consent & Autoblock for GDPR/CCPA plugin, affecting versions through 1.0.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

WordPress Board Election Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Board Election plugin, specifically in versions through 1.0.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed.

2.0
Jan 16, 2025

WordPress Simple Project Manager Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Simple Project Manager plugin, specifically in versions through 1.2.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are stored and executed later.

2.0
Jan 16, 2025

WordPress Universal Analytics Injector Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Universal Analytics Injector plugin, specifically in versions through 1.0.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser session.

2.0
Jan 16, 2025

WordPress My-Related-Posts Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress My-Related-Posts plugin, specifically in versions through 1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the site.

2.0
Jan 16, 2025

WordPress ECT Add to Cart Button Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress ECT Add to Cart Button plugin, affecting versions through 1.4. This vulnerability allows for Stored Cross-Site Scripting, where an attacker could trick users with higher privileges into performing actions that could lead to the execution of malicious scripts.

2.0
Jan 16, 2025

WordPress Visit Site Link Enhanced Plugin CSRF Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Visit Site Link Enhanced plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress RSS News Scroller Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress RSS News Scroller plugin, specifically in versions through 2.0.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

WordPress MD Custom Content Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress MD Custom Content plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could inject malicious scripts into the content.

2.0
Jan 16, 2025

WordPress EmailShroud Plugin Cross-Site Request Forgery Vulnerability Allowing Reflected Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress EmailShroud plugin, specifically in versions through 2.2.1. This vulnerability allows for Reflected Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts.

2.0
Jan 16, 2025

WordPress WP VTiger Synchronization Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress WP VTiger Synchronization plugin, specifically in versions through 1.1.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could introduce malicious scripts that are permanently stored and executed later.

2.0
Jan 16, 2025

Myriad Solutionz Stars SMTP Mailer Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Myriad Solutionz Stars SMTP Mailer plugin for WordPress, affecting versions through 1.7. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 16, 2025

EditionGuard for WooCommerce Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the EditionGuard for WooCommerce – eBook Sales with DRM plugin, affecting versions through 3.4.2. This vulnerability allows for improper neutralization of input, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 16, 2025

Scott Swezey Easy Tynt WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Scott Swezey Easy Tynt WordPress plugin, affecting versions through 0.2.5.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

WordPress Scroll Top Advanced Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Scroll Top Advanced plugin, affecting versions through 2.5. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when users visit the site.

1.7
Jan 16, 2025

WordPress Shockingly Big IE6 Warning Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Shockingly Big IE6 Warning plugin, affecting versions through 1.6.3. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could trick users with higher privileges into performing actions that could lead to the execution of harmful scripts.

2.0
Jan 16, 2025

MarvinLabs WP PT-Viewer Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the MarvinLabs WP PT-Viewer WordPress plugin, affecting versions through 2.0.2. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 16, 2025

Capa Wp-Scribd-List Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Capa Wp-Scribd-List plugin for WordPress, specifically in versions through 1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.

2.0
Jan 16, 2025

David Marcucci Password Protect WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Password Protect Plugin for WordPress, specifically in versions through 0.8.1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where a malicious actor could exploit the CSRF to inject harmful scripts that are then executed when a user accesses the affected content.

2.0
Jan 16, 2025

WordPress Easy EU Cookie Law Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Easy EU Cookie Law plugin, affecting versions through 1.3.3.1. This vulnerability arises from improper input handling during web page generation, allowing malicious actors to inject scripts that are executed when users visit the affected site.

1.7
Jan 16, 2025

WordPress AlTi5 AlT Report Plugin Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the WordPress AlTi5 AlT Report plugin, affecting versions through 1.12.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.

2.0
Jan 16, 2025

WordPress Mass Custom Fields Manager Cross-Site Request Forgery Vulnerability Allowing Reflected Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Mass Custom Fields Manager plugin, specifically in versions through 1.5. This vulnerability allows for Reflected Cross-Site Scripting (XSS) attacks. The issue arises from the plugin's failure to properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.

2.0
Jan 16, 2025

Altima Lookbook Free for WooCommerce Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Altima Lookbook Free for WooCommerce plugin, affecting versions through 1.1.0. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the affected site.

2.0
Jan 16, 2025

Wizcrew Technologies Go Social WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wizcrew Technologies Go Social WordPress plugin, specifically in versions through 1.0. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed by users.

2.0
Jan 16, 2025

WordPress Marquee Style RSS News Ticker Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Marquee Style RSS News Ticker plugin, affecting versions through 3.2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 16, 2025

Smackcoders SendGrid for WordPress Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the Smackcoders SendGrid for WordPress plugin, affecting versions through 1.4. This vulnerability arises from improperly configured access control security levels, which can be exploited to perform actions without the necessary authorization.

1.8
Jan 16, 2025

Matrix Media Repo Untrusted File Format Thumbnailing Vulnerability Invoking External Decoders

A vulnerability exists in Matrix Media Repo (MMR) versions prior to 1.3.8, allowing users to upload files that falsely claim to be SVG or JPEGXL. When these files are processed for thumbnails, they can trigger different decoders in ImageMagick. In certain ImageMagick installations, this could enable the execution of Ghostscript to decode the file, potentially leading to the execution of malicious code. Similarly, if MP4 thumbnailers are enabled, the issue could arise with the ffmpeg installation, exploiting the same flaw by uploading a file that pretends to be an MP4.

3.0
Jan 16, 2025

Zulip Server Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in Zulip Server versions 7.0 and above. When a server hosts multiple organizations, an unauthenticated user can send a request to the '/api/v1/fetch_api_key' endpoint and determine if a specific email address is associated with a user account. This issue arises because the server responds with an 'invalid subdomain' error when an email address does not exist on the requested subdomain, but does on another, allowing the attacker to infer the existence of the account.

5.1
Jan 16, 2025

OpenObserve Improper Authorization Vulnerability in User Management Endpoint Allows Admin to Remove Root User

A vulnerability exists in OpenObserve versions prior to 0.14.1, specifically in the user management endpoint '/api/{org_id}/users/{email_id}'. This vulnerability allows an 'Admin' role user to remove a 'Root' user from the organization, violating the intended privilege hierarchy. The issue arises from insufficient role checks in the 'remove_user_from_org' function, which fails to prevent an 'Admin' user from targeting a 'Root' user for removal. Consequently, an 'Admin' user can eliminate critical 'Root' accounts, potentially gaining full control by removing the highest-privileged users.

3.2
Jan 16, 2025

Matrix Media Repo Denial-of-Service Vulnerability via Memory Exhaustion

A denial-of-service vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.8. This issue arises because MMR can parse large amounts of JSON data returned from other servers, leading to excessive memory consumption and exhaustion of available resources. The vulnerability can be exploited during normal operation when MMR processes requests to resource owners that return substantial JSON payloads.

4.1
Jan 16, 2025

Matrix Media Repo Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.8. This vulnerability allows MMR to access and serve content from internal networks under certain conditions. The issue arises when MMR is manipulated to make requests to internal resources, potentially exposing sensitive data or services.

4.3
Jan 16, 2025

Matrix Media Repo Unbounded Disk Consumption Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.5. This issue allows an unauthenticated attacker to cause excessive disk usage by inducing the application to download and store large quantities of remote media files. The vulnerability primarily affects instances using a file-backed storage option or those that self-host an S3 storage system, leading to a disk fill attack. When the disk becomes full, authenticated users are unable to upload new media, causing a denial-of-service condition. In cases where cloud-based S3 storage is used, the vulnerability could result in significant service charges instead of a denial-of-service impact.

4.1
Jan 16, 2025

Matrix Media Repo Unauthenticated Content Injection Vulnerability

A vulnerability in Matrix Media Repo (MMR) versions prior to 1.3.5 allows unauthenticated remote participants to download and cache media from a remote homeserver to the local media repository. This content can then be accessed from the local homeserver without authentication. As a result, unauthenticated remote adversaries can exploit this feature to introduce undesirable content into the media repository.

4.1
Jan 16, 2025

Mattermost Mobile Attachment Processing Vulnerability Leading to Denial-of-Service

A denial-of-service vulnerability has been identified in Mattermost Mobile versions through 2.22.0. The issue arises because the application fails to properly manage posts with attachments that include fields not convertible to a string. This flaw allows an attacker to create and send such a post to a channel, causing the mobile application to crash.

1.0
Jan 16, 2025

Mattermost Denial-of-Service Vulnerability in Post Attachments

A denial-of-service vulnerability has been identified in Mattermost versions 10.2.x through 10.2.0, 9.11.x through 9.11.5, 10.0.x through 10.0.3, and 10.1.x through 10.1.3. The issue arises because the application fails to properly process posts with attachments that include fields unable to be converted to a string. This flaw allows an attacker to crash the web application by creating and sending such a post to a channel.

2.9
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in formDMZ.cgi Allowing Unauthenticated DMZ Configuration

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the DMZ service settings of the device by sending a crafted POST request. The issue arises in the component formDMZ.cgi, where inadequate access controls permit unauthorized modifications to the DMZ configuration.

6.8
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in URL Filter Component

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the device's URL filter settings by sending a crafted POST request.

6.3
Jan 16, 2025

D-Link DIR-816 Information Disclosure Vulnerability in d_status.asp Component

A vulnerability allowing information disclosure has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability arises in the d_status.asp component, where unauthenticated attackers can access sensitive information by sending a crafted POST request.

5.4
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in AGL Service

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the component form2alg.cgi. This vulnerability allows unauthenticated attackers to manipulate the AGL service of the device by sending a crafted POST request.

6.3
Jan 16, 2025

D-Link DIR-816 Access Control Vulnerability in form2PortriggerRule.cgi Allowing Unauthenticated Port Triggering

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. The issue allows unauthenticated attackers to manipulate the port triggering settings of the device by sending a crafted POST request. This vulnerability arises from inadequate access controls in the affected CGI component, form2PortriggerRule.cgi.

6.7