In all WooCommerce versions up to, and including 3.5.1 a medium severity vulnerability CVE-2024-6458 was detected. Attackers with basic access can change post titles without permission. This can also lead to harmful scripts being saved, which can affect admins who view these posts. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6458.
Read more E-commerceIn Magento versions prior to 20.10.1 a medium severity vulnerability CVE-2024-41676 was detected. There is a security issue where admins can accidentally add harmful code in these settings: design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt. These settings allow text or image URLs but may unintentionally include dangerous code. This issue is fixed in version 20.10.1 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41676.
Read more E-commerceIn Dolibarr ERP CRM versions before 19.0.2-php8.2 a high severity vulnerability CVE-2024-40137 was detected. A vulnerability in the Computed field parameter of the Users Module Setup in Dolibarr ERP CRM allows remote code execution. This issue is fixed in versions 19.0.2-php8.2 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-40137.
In Joomla versions 3.0.0-3.10.15-elts, 4.0.0-4.4.5, 5.0.0-5.1.1 a low severity vulnerability CVE-2024-26279 was detected. This vulnerability allows attackers to access sensitive data via cross-scripting. There is no fix to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-26279/.
Read more CMSIn Joomla versions from 3.7.0 through 3.10.15, from 4.0.0 through 4.4.5, and from 5.0.0 through 5.1.1 a medium severity vulnerability CVE-2024-26278 was detected. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions or data theft. To fix this problem, users should upgrade Joomla to one of the following versions 3.10.16, 4.4.6, or 5.1.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-26278.
In OpenVPN version 2.0.4 a low severity vulnerability CVE-2024-28820 was detected. This vulnerability allows attackers to access sensitive data. There is no fix to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-28820/.
Read more CMSIn WordPress Core versions up to 6.5.5 a medium severity vulnerability CVE-2024-6307 was detected. This vulnerability allows attackers to insert harmful web scripts into pages. These scripts can run whenever a user visits the affected page. To fix this problem, users should upgrade WordPress Core to one of the following versions: 5.9.10, 6.0.9, 6.1.7, 6.2.6, 6.3.5, 6.4.5 or 6.5.5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6307.
Read more CMSIn WordPress versions from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, and from 5.9 through 5.9.9 a medium severity vulnerability CVE-2024-31111 was detected. This vulnerability allows attackers to insert harmful web scripts into pages to gain access to the system and sensitive information. To fix this problem, users should upgrade WordPress to version 6.5.5 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-31111.
Read more CMSIn WordPress version 6.5.5 a medium severity vulnerability CVE-2024-6305 was detected. This vulnerability allows attackers to inject arbitrary web scripts. There is no solution to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6305/.
Read more CMS