| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-8959 | WP Adminify – Best WordPress Custom Dashboard Plugin <= 4.0.1.6 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | litonice13 | WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer | Medium | 6.4 | 2024-10-24 11:34:09 | Deep Dive |
| CVE-2024-49307 | WordPress Admin Management Xtended plugin <= 2.4.6 - Cross Site Scripting (XSS) vulnerability | wpseek | Admin Management Xtended | Medium | 6.5 | 2024-10-17 18:49:39 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-9291 | kalvinGit kvf-admin XML File cross site scripting | kalvinGit | kvf-admin | Low | 3.5 | 2024-09-27 21:00:09 | Deep Dive |
| CVE-2024-9280 | kalvinGit kvf-admin FileUploadKit.java fileUpload unrestricted upload | kalvinGit | kvf-admin | Medium | 4.7 | 2024-09-27 12:00:08 | Deep Dive |
| CVE-2024-9279 | funnyzpc Mee-Admin User Center index cross site scripting | funnyzpc | Mee-Admin | Low | 2.4 | 2024-09-27 11:31:05 | Deep Dive |
| CVE-2024-8155 | ContiNew Admin tree sql injection | ContiNew | Admin | Medium | 4.7 | 2024-08-25 23:00:09 | Deep Dive |
| CVE-2024-8150 | ContiNew Admin user sql injection | ContiNew | Admin | Medium | 4.7 | 2024-08-25 22:00:05 | Deep Dive |
| CVE-2024-8003 | Go-Tribe gotribe-admin Log routes.go InitRoutes deserialization | Go-Tribe | gotribe-admin | Low | 3.5 | 2024-08-20 13:31:05 | Deep Dive |
| CVE-2024-39318 | Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget | ibexa | admin-ui | Medium | 5.4 | 2024-07-31 15:38:48 | Deep Dive |
| CVE-2024-41109 | Pimcore vulnerable to disclosure of system and database information behind /admin firewall | pimcore | admin-ui-classic-bundle | Medium | 6.3 | 2024-07-30 14:43:14 | Deep Dive |
| CVE-2024-6549 | Admin Post Navigation <= 2.1 - Unauthenticated Full Path Disclosure | coffee2code | Admin Post Navigation | Medium | 5.3 | 2024-07-27 01:51:05 | Deep Dive |
| CVE-2024-6545 | Admin Trim Interface <= 3.5.1 - Unauthenticated Full Path Disclosure | coffee2code | Admin Trim Interface | Medium | 5.3 | 2024-07-27 01:51:04 | Deep Dive |
| CVE-2024-6548 | Add Admin JavaScript <= 2.0 - Unauthenticated Full Path Dislcosure | coffee2code | Add Admin JavaScript | Medium | 5.3 | 2024-07-27 01:51:03 | Deep Dive |
| CVE-2024-6547 | Add Admin CSS <= 2.0.1 - Unauthenticated Full Path Dislcosure | coffee2code | Add Admin CSS | Medium | 5.3 | 2024-07-27 01:51:00 | Deep Dive |
| CVE-2024-38788 | WordPress UiPress lite plugin <= 3.4.06 - SQL Injection vulnerability | Bởi Admin 2020 | UiPress lite | High | 7.6 | 2024-07-22 10:06:01 | Deep Dive |
| CVE-2024-38725 | WordPress Admin Dashboard RSS Feed plugin <= 3.1 - Cross Site Scripting (XSS) vulnerability | Webstix | Admin Dashboard RSS Feed | Medium | 5.9 | 2024-07-20 07:19:18 | Deep Dive |
| CVE-2024-37418 | WordPress Church Admin plugin <= 4.4.6 - Arbitrary File Upload vulnerability | andy_moyle | Church Admin | - | - | 2024-07-09 10:15:29 | Deep Dive |
| CVE-2024-39322 | aimeos/ai-admin-jsonadm improper access control vulnerability allows editors to remove required records | aimeos | ai-admin-jsonadm | Medium | 5.5 | 2024-07-02 20:19:02 | Deep Dive |
| CVE-2024-39324 | aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services | aimeos | ai-admin-graphql | Low | 3.8 | 2024-07-02 20:09:23 | Deep Dive |