Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | wp-affiliate-platform | 0 ~ 6.5.1 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-4272 | Support SVG < 1.1.0 - Stored XSS via SVG Upload | |
| CVE-2024-3964 | Product Enquiry for WooCommerce < 3.1.8 - Admin+ Stored XSS | |
| CVE-2024-4602 | Embed Peertube Playlist < 1.10 - Editor+ Stored XSS | |
| CVE-2024-3919 | OpenPGP Form Encryption for WordPress < 1.5.1 - Contributor+ Stored XSS | |
| CVE-2024-3963 | RafflePress Lite < 1.12.14 - Editor+ Stored XSS | |
| CVE-2024-3026 | WordPress Button Plugin MaxButtons < 9.7.8 - Editor+ Stored XSS | |
| CVE-2024-3710 | Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS | |
| CVE-2024-3632 | Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRF | |
| CVE-2024-2870 | Swift Framework < 2024.04.30 - Reflected XSS | |
| CVE-2024-3751 | Seriously Simple Podcasting < 3.3.0 - Admin+ Stored XSS | |
| CVE-2024-4217 | Shortcodes Ultimate Pro < 7.1.5 - Contributor+ Stored Cross-Site Scripting XSS | |
| CVE-2024-4269 | SVG Block < 1.1.20 - Author+ Stored XSS via SVG File Upload | |
| CVE-2024-4977 | Index WP MySQL For Speed < 1.4.18 - Admin+ Reflected XSS | |
| CVE-2024-4752 | EventON < 2.2.15 - Admin+ Stored Cross-Site Scripting via event subtitle | |
| CVE-2024-5028 | CM WordPress Search And Replace Plugin < 1.3.9 - Plugin Reset via CSRF | |
| CVE-2024-5002 | User Submitted Posts < 20240516 - Admin+ Stored XSS | |
| CVE-2024-5034 | SULly < 4.3.1 - Plugin Reset via CSRF | |
| CVE-2024-5033 | SULly < 4.3.1 - Admin+ Stored XSS via CSRF | |
| CVE-2024-5032 | SULly < 4.3.1 - Reflected XSS | |
| CVE-2024-5076 | WP eMember < 10.6.6 - Bulk Delete via CSRF |
Showing top 20 of 45 CVEs. View all on vendor page → →
No comments yet