| CVE-2024-29932 | WordPress WordPress Meta Data and Taxonomies Filter (MDTF) plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability | realmag777 | WordPress Meta Data and Taxonomies Filter (MDTF) | Medium | 6.5 | 2024-03-27 10:11:41 | Deep Dive |
| CVE-2024-29906 | WordPress MDTF – Meta Data and Taxonomies Filter plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability | realmag777 | WordPress Meta Data and Taxonomies Filter (MDTF) | Medium | 6.5 | 2024-03-27 06:53:23 | Deep Dive |
| CVE-2024-1203 | Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce <= 7.0.7 - Authenticated (Subscriber+) SQL Injection | tatvic | Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels | High | 8.8 | 2024-03-13 15:26:59 | Deep Dive |
| CVE-2024-0786 | Conversios <= 7.0.7 - Authenticated (Subscriber+) SQL Injection via ee_syncProductCategory | tatvic | Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels | High | 8.8 | 2024-02-28 08:33:13 | Deep Dive |
| CVE-2023-6526 | Meta Box – WordPress Custom Fields Framework <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | metabox | Meta Box | Medium | 6.4 | 2024-02-05 21:21:38 | Deep Dive |
| CVE-2024-23347 | Meta Spark Studio 安全漏洞 | Meta Platforms, Inc | Meta Spark Studio | 超危 | - | 2024-01-16 17:57:20 | Deep Dive |
| CVE-2023-5776 | Post Meta Data Manager <= 1.2.1 - Cross-Site Request Forgery to Post, Term, and User Meta Deletion | gandhihitesh9 | Post Meta Data Manager | Medium | 4.3 | 2023-11-21 08:32:48 | Deep Dive |
| CVE-2023-32514 | WordPress Google Site Verification plugin using Meta Tag Plugin <= 1.2 is vulnerable to Cross Site Request Forgery (CSRF) | Himanshu Parashar | Google Site Verification plugin using Meta Tag | Medium | 5.4 | 2023-11-18 22:24:57 | Deep Dive |
| CVE-2023-46618 | WordPress Category SEO Meta Tags Plugin <= 2.5 is vulnerable to Cross Site Request Forgery (CSRF) | Bala Krishna, Sergey Yakovlev | Category SEO Meta Tags | Medium | 4.3 | 2023-11-13 00:47:00 | Deep Dive |
| CVE-2023-4823 | WP Meta and Date Remover < 2.2.0 - Subscriber+ Stored XSS | Unknown | WP Meta and Date Remover | 中危 | - | 2023-10-31 13:54:43 | Deep Dive |
| CVE-2023-5425 | Post Meta Data Manager <=1.2.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | gandhihitesh9 | Post Meta Data Manager | High | 8.8 | 2023-10-28 11:06:04 | Deep Dive |
| CVE-2023-5426 | Post Meta Data Manager <=1.2.0 - Missing Authorization to User, Term, and Post Meta Deletion | gandhihitesh9 | Post Meta Data Manager | High | 7.5 | 2023-10-28 11:06:04 | Deep Dive |
| CVE-2023-46091 | WordPress Category SEO Meta Tags Plugin <= 2.5 is vulnerable to Cross Site Scripting (XSS) | Bala Krishna, Sergey Yakovlev | Category SEO Meta Tags | Medium | 5.9 | 2023-10-27 07:27:26 | Deep Dive |
| CVE-2023-30967 | Gotham Orbital Simulator path traversal | Palantir | com.palantir.meta:orbital-simulator | Critical | 9.8 | 2023-10-25 23:18:24 | Deep Dive |
| CVE-2023-5654 | React Developer Tools 安全漏洞 | Meta | React Developer Tools Extension | Medium | 6.5 | 2023-10-19 14:28:24 | Deep Dive |
| CVE-2023-44998 | WordPress Category Meta Plugin <= 1.2.8 is vulnerable to Cross Site Request Forgery (CSRF) | josecoelho, Randy Hoyt, steveclarkcouk, Vitaliy Kukin, Eric Le Bail, Tom Ransom | Category Meta plugin | Medium | 4.3 | 2023-10-12 12:10:05 | Deep Dive |
| CVE-2023-45239 | Facebook Tacacs+ 安全漏洞 | Meta | tac_plus | 超危 | - | 2023-10-06 17:16:17 | Deep Dive |
| CVE-2023-41650 | WordPress Remove/hide Author, Date, Category Like Entry-Meta Plugin <= 2.1 is vulnerable to Cross Site Request Forgery (CSRF) | Venugopal | Remove/hide Author, Date, Category Like Entry-Meta | Medium | 4.3 | 2023-10-06 14:33:20 | Deep Dive |
| CVE-2023-1661 | Display post meta, term meta, comment meta, and user meta <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | trasweb | Display post meta, term meta, comment meta, and user meta | Medium | 6.4 | 2023-05-31 03:36:10 | Deep Dive |
| CVE-2023-23712 | WordPress User Meta Manager Plugin <= 3.4.9 is vulnerable to Cross Site Request Forgery (CSRF) | User Meta Manager | User Meta Manager | Medium | 5.4 | 2023-05-22 08:27:37 | Deep Dive |