| CVE-2024-8899 | Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 4.3 | 2024-11-26 11:04:30 | Deep Dive |
| CVE-2024-53261 | Cross-Site Scripting attack (XSS) on dev mode 404 page in SvelteKit | sveltejs | kit | - | - | 2024-11-25 19:15:28 | Deep Dive |
| CVE-2024-53262 | Unescaped error message included on error page in SvelteKit | sveltejs | kit | - | - | 2024-11-25 19:07:20 | Deep Dive |
| CVE-2024-10873 | LA-Studio Element Kit for Elementor <= 1.4.2 - Authenticated (Contributor+) Local File Inclusion | choijun | LA-Studio Element Kit for Elementor | High | 8.8 | 2024-11-23 04:32:20 | Deep Dive |
| CVE-2024-11432 | SuevaFree Essential Kit <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | alexvtn | SuevaFree Essential Kit | Medium | 6.4 | 2024-11-21 02:06:30 | Deep Dive |
| CVE-2024-51856 | WordPress Moose Elementor Kit plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability | ibllex | Moose Elementor Kit | Medium | 6.5 | 2024-11-19 16:31:32 | Deep Dive |
| CVE-2024-21539 | ESLint Rewrite 安全漏洞 | - | @eslint/plugin-kit | High | 7.5 | 2024-11-19 05:00:03 | Deep Dive |
| CVE-2024-9541 | News Kit Elementor Addons <= 1.2.1 - Authenticated (Contributor+) Sensitive Information Exposure via Canvas Menu Elementor Template | blazethemes | News Kit Addons For Elementor | Medium | 4.3 | 2024-10-22 07:36:35 | Deep Dive |
| CVE-2024-22034 | Crafted projects can overwrite special files in the .osc config directory | SUSE | SUSE Linux Enterprise Desktop 15 SP5 | Medium | 5.5 | 2024-10-16 13:46:08 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-47390 | WordPress Jeg Elementor Kit plugin <= 2.6.8 - Cross Site Scripting (XSS) vulnerability | jegtheme | Jeg Elementor Kit | Medium | 6.5 | 2024-10-05 14:45:26 | Deep Dive |
| CVE-2024-47628 | WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.3 - Cross Site Scripting (XSS) vulnerability | LA-Studio | LA-Studio Element Kit for Elementor | Medium | 6.5 | 2024-10-05 13:23:04 | Deep Dive |
| CVE-2024-47629 | WordPress Ultimate Store Kit Elementor Addons plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerability | bdthemes | Ultimate Store Kit Elementor Addons | Medium | 6.5 | 2024-10-05 13:21:53 | Deep Dive |
| CVE-2024-8030 | Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.0.3 - Unauthenticated PHP Object Injection | bdthemes | Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | Critical | 9.8 | 2024-08-28 02:05:47 | Deep Dive |
| CVE-2024-6804 | Jeg Elementor Kit <= 2.6.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | Medium | 6.4 | 2024-08-27 06:48:04 | Deep Dive |
| CVE-2024-5335 | Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 - Unauthenticated PHP Object Injection | bdthemes | Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | Critical | 9.8 | 2024-08-21 08:29:15 | Deep Dive |
| CVE-2024-43342 | WordPress Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin <= 1.6.4 - Cross Site Scripting (XSS) vulnerability | BdThemes | Ultimate Store Kit Elementor Addons | Medium | 6.5 | 2024-08-18 13:22:30 | Deep Dive |
| CVE-2024-43210 | WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.2 - Cross Site Scripting (XSS) vulnerability | LA-Studio | LA-Studio Element Kit for Elementor | Medium | 6.5 | 2024-08-12 21:46:25 | Deep Dive |
| CVE-2024-37487 | WordPress WP Directory Kit plugin <= 1.3.5 - Reflected Cross Site Scripting (XSS) vulnerability | wpdirectorykit.com | WP Directory Kit | High | 7.1 | 2024-07-21 07:32:26 | Deep Dive |
| CVE-2024-37550 | WordPress Template Kit – Export plugin <= 1.0.22 - Cross Site Scripting (XSS) vulnerability | Envato | Template Kit – Export | Medium | 5.9 | 2024-07-21 06:57:25 | Deep Dive |