| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-6996 | Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Code Injection | josevega | Display custom fields in the frontend – Post and User Profile Fields | High | 8.8 | 2024-02-05 21:22:03 | Deep Dive |
| CVE-2024-0371 | Views for WPForms <= 3.2.2 - Missing Authorization via create_view | aman086 | Views for WPForms – Display & Edit WPForms Entries on your site frontend | Medium | 4.3 | 2024-02-05 21:21:57 | Deep Dive |
| CVE-2024-0370 | Views for WPForms <= 3.2.2 - Missing Authorization via save_view | aman086 | Views for WPForms – Display & Edit WPForms Entries on your site frontend | Medium | 4.3 | 2024-02-05 21:21:41 | Deep Dive |
| CVE-2024-0374 | Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via create_view | aman086 | Views for WPForms – Display & Edit WPForms Entries on your site frontend | Medium | 4.3 | 2024-02-05 21:21:40 | Deep Dive |
| CVE-2023-6982 | Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via vg_display_data | josevega | Display custom fields in the frontend – Post and User Profile Fields | Medium | 6.4 | 2024-02-05 21:21:39 | Deep Dive |
| CVE-2024-0372 | Views for WPForms <= 3.2.2 - Missing Authorization via get_form_fields | aman086 | Views for WPForms – Display & Edit WPForms Entries on your site frontend | Medium | 4.3 | 2024-02-05 21:21:38 | Deep Dive |
| CVE-2023-6983 | Display custom fields in the frontend – Post and User Profile Fields <= 1.2.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Meta Disclosure | josevega | Display custom fields in the frontend – Post and User Profile Fields | Medium | 4.3 | 2024-02-05 21:21:32 | Deep Dive |
| CVE-2023-51411 | WordPress Frontend Admin by DynamiApps Plugin <= 3.18.3 is vulnerable to Arbitrary File Upload | Shabti Kaplan | Frontend Admin by DynamiApps | Critical | 10.0 | 2023-12-29 13:50:21 | Deep Dive |
| CVE-2023-5105 | Frontend File Manager < 22.6 - Editor+ Arbitrary File Download | Unknown | Frontend File Manager Plugin | - | - | 2023-12-04 21:27:46 | Deep Dive |
| CVE-2023-1982 | Front Editor <= 4.0.4 - Admin+ Stored XSS | Unknown | Guest posting / Frontend Posting wordpress plugin | 中危 | - | 2023-08-30 14:22:03 | Deep Dive |
| CVE-2023-30952 | Foundry Issues reporterPath phishing by parameter injection | Palantir | com.palantir.foundry:foundry-frontend | Medium | 5.0 | 2023-08-03 21:12:54 | Deep Dive |
| CVE-2023-30958 | DOM XSS in Developer mode dashboard via redirect GET parameter | Palantir | com.palantir.foundry:foundry-frontend | Medium | 4.7 | 2023-08-03 21:09:10 | Deep Dive |
| CVE-2023-30963 | Stored XSS in Foundry Slate Query Dropdown menu | Palantir | com.palantir.foundry:foundry-frontend | Medium | 5.4 | 2023-07-10 21:04:09 | Deep Dive |
| CVE-2023-22835 | Denial of Service in Foundry Issues | Palantir | com.palantir.foundry:foundry-frontend | High | 7.7 | 2023-07-10 20:58:15 | Deep Dive |
| CVE-2021-4383 | WP Quick FrontEnd Editor <= 5.5 - Authenticated (Subscriber+) Content Injection | labibahmed42 | WP Quick FrontEnd Editor – WordPress Plugin | High | 8.1 | 2023-06-07 01:51:53 | Deep Dive |
| CVE-2021-4378 | WP Quick FrontEnd Editor <= 5.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting | labibahmed42 | WP Quick FrontEnd Editor – WordPress Plugin | Medium | 6.4 | 2023-06-07 01:51:50 | Deep Dive |
| CVE-2021-4369 | Frontend File Manager <= 18.2 - Unauthenticated Content Injection | nmedia | Frontend File Manager Plugin | Medium | 5.8 | 2023-06-07 01:51:42 | Deep Dive |
| CVE-2021-4371 | WP Quick FrontEnd Editor <= 5.5 - Authenticated Settings Change | labibahmed42 | WP Quick FrontEnd Editor – WordPress Plugin | Medium | 4.3 | 2023-06-07 01:51:42 | Deep Dive |
| CVE-2021-4368 | Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload | nmedia | Frontend File Manager Plugin | Critical | 9.9 | 2023-06-07 01:51:38 | Deep Dive |
| CVE-2021-4365 | Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting | nmedia | Frontend File Manager Plugin | High | 7.2 | 2023-06-07 01:51:37 | Deep Dive |