CVE-2024-9702 – The Social Rocket for WordPress Stored Cross-Site Scripting

CVE ID : CVE-2024-9702 Published : Jan. 7, 2025, 6:15 a.m. | 25 minutes ago Description : The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘socialrocket-floating’ shortcode in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user […]

CVE-2024-8857 – WordPress Auction Plugin Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-8857 Published : Jan. 7, 2025, 6:15 a.m. | 25 minutes ago Description : The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks. Severity: 0.0 | NA Visit the link […]

CVE-2024-8855 – “Auction Plugin SQL Injection Vulnerability in WordPress”

CVE ID : CVE-2024-8855 Published : Jan. 7, 2025, 6:15 a.m. | 25 minutes ago Description : The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks Severity: 0.0 | NA Visit the link for […]

CVE-2024-7696 – AXIS Camera Station Audit Log Tampering and Attack Vector Vulnerability

The following table lists the changes that have been made to the CVE-2024-7696 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 07, 2025 Action […]

CVE-2024-12633 – JoomSport WordPress Reflected Cross-Site Scripting (XSS)

CVE ID : CVE-2024-12633 Published : Jan. 7, 2025, 6:15 a.m. | 25 minutes ago Description : The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization and […]