Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation.
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently se
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.