All 5 CVE vulnerabilities found in Tumult Hype Animations, with AI-generated Chinese analysis, references, and POCs.
Vendor: Tumult Inc.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-30461 | WordPress Tumult Hype Animations plugin <= 1.9.11 - CSRF to XSS vulnerability CWE-79 | 7.1 | High | 2026-01-05 |
| CVE-2024-11082 | Tumult Hype Animations <= 1.9.15 - Authenticated (Author+) Arbitrary File Upload via hypeanimations_panel Function CWE-434 | 9.9 | Critical | 2024-11-28 |
| CVE-2024-10543 | Tumult Hype Animations <= 1.9.14 - Missing Authorization CWE-862 | 4.3 | Medium | 2024-11-06 |
| CVE-2024-30460 | WordPress Tumult Hype Animations plugin <= 1.9.11 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 | 4.3 | Medium | 2024-03-29 |
| CVE-2024-2890 | WordPress Tumult Hype Animations plugin <= 1.9.12 - Arbitrary File Upload vulnerability CWE-434 | 9.1 | Critical | 2024-03-28 |
All 5 known CVE vulnerabilities affecting Tumult Hype Animations with full Chinese analysis, references, and POCs where available.