In Umbraco version 14.3.1 a medium severity vulnerability CVE-2024-55488 was detected. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload, resulting in stored cross-site scripting (XSS). Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-55488.
Read more CMSIn Meta Data and Taxonomies Filter plugin for WordPress versions up to and including 1.3.3.6 a medium severity vulnerability CVE-2024-13340 was detected. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages via the ‘mdf_results_by_ajax’ shortcode, due to insufficient input sanitization and output escaping on user-supplied attributes. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13340.
Read more CMSIn Directus versions prior to 11.2.0 a medium severity vulnerability CVE-2025-24353 was detected. This vulnerability allows attackers to exploit the item sharing feature to specify an arbitrary role, potentially escalating privileges and accessing fields that should otherwise remain hidden. To address this issue, users should upgrade Directus to version 11.2.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-24353.
Read more CMSIn Umbraco versions 14.0.0 up to 14.3.1 and 15.0.0 up to 15.1.1 a medium severity vulnerability CVE-2025-24011 was detected. This vulnerability allows attackers to determine if an account exists by analyzing response codes and timing from the management API. To address this issue, users should upgrade Umbraco to versions 14.3.2 or 15.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-24011.
Read more CMSIn SuiteCRM version 7.12.7 a high severity vulnerability CVE-2022-45186 was detected. This vulnerability allows authenticated users to recover arbitrary fields from the database. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-45186.
Read more CRMIn MonicaHQ version 4.1.2 a medium severity vulnerability CVE-2024-54999 was detected. This vulnerability allows attackers to exploit a Client-Side Injection via the `last_name` parameter in the General Information module. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-54999.
Read more CRMIn MonicaHQ version 4.1.1 a medium severity vulnerability CVE-2024-54997 was detected. This vulnerability allows attackers to exploit an authenticated Client-Side Injection via the `entry` text field at `/journal/entries/ID/edit`. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-54997.
Read more CRMIn Drupal Node Access Rebuild Progressive versions from 7.X-1.0 to before 7.X-1.2 a medium severity vulnerability CVE-2024-13249 was detected. This vulnerability allows attackers to influence target behavior via framing. To address this issue, users should upgrade Node Access Rebuild Progressive to version 7.X-1.2 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-13249.
Read more CMSIn Ultimate Gift Cards for WooCommerce Plugin versions up to 2.9.1 a high severity vulnerability CVE-2024-11423 was detected. This vulnerability allows unauthenticated attackers to modify gift card balances via several REST API endpoints, such as /wp-json/gifting/recharge-giftcard, without making a payment or purchasing anything. To address this issue, users should upgrade to version 2.9.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11423.
Read more E-commerce