In GitLab CE/EE versions 10.6 up to 16.9.7, 16.10 up to 16.10.5, and 16.11 up to 16.11.2 a medium severity vulnerability CVE-2024-1211 was detected. This vulnerability allows attackers to potentially exploit cross-site request forgery (CSRF) on GitLab instances configured to use JWT as an OmniAuth provider. To address this issue, users should upgrade GitLab CE/EE to versions 16.11.2, 16.10.5 or 16.9.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-1211.
Read more Developer ToolsIn GitLab CE/EE versions 15.5 up to 16.9.7, 16.10 up to 16.10.5, and 16.11 up to 16.11.2 a low severity vulnerability CVE-2023-6195 was detected. This vulnerability allows attackers to exploit server-side request forgery (SSRF) by using a malicious URL in the markdown image value when importing a GitHub repository. To address this issue, users should upgrade GitLab CE/EE to versions 16.11.2, 16.10.5 or 16.9.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-6195.
Read more Developer ToolsIn The AI Infographic Maker plugin for WordPress versions 4.9.0 and prior a medium severity vulnerability CVE-2024-12415 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes due to improper validation of values before running do_shortcode. To address this issue, users should upgrade The AI Infographic Maker plugin to version 5.0.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12415.
Read more CMS Business and Enterprise SolutionsIn WP DataTable plugin for WordPress versions 0.2.6 and prior a medium severity vulnerability CVE-2024-13566 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the ‘id’ parameter, leading to Stored Cross-Site Scripting. To address this issue, users should upgrade WP DataTable plugin to version 0.2.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13566.
Read more CMS Business and Enterprise SolutionsIn WP Image Uploader plugin for WordPress versions 1.0.1 and prior a high severity vulnerability CVE-2024-13720 was detected. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validation in the `gky_image_uploader_main_function()` function, potentially leading to remote code execution if critical files, such as`wp-config.php`, are deleted. To address this issue, users should upgrade to a patched version once available. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13720.
Read more CMS Business and Enterprise SolutionsIn StageShow plugin for WordPress versions 9.8.6 and prior a medium severity vulnerability CVE-2024-13705 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via improper escaping in the `remove_query_arg` function, potentially executing scripts when a user clicks on a malicious link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13705.
Read more CMS Business and Enterprise SolutionsIn Elementor Website Builder Pro plugin for WordPress versions 3.25.10 and prior a medium severity vulnerability CVE-2024-8494 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to extract sensitive data, including the content of Private, Pending, and Draft Templates, via the `elementor-template` shortcode. To address this issue, users should upgrade Elementor Website Builder Pro plugin to version 3.25.11 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8494.
Read more CMSIn iTop version 16.0 a high severity vulnerability CVE-2024-53588 was detected. This vulnerability allows attackers to run malicious code on the system by tricking iTop VPN into loading a fake DLL file. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-53588.
In Target Video Easy Publish plugin for WordPress versions up to and including 3.8.3 a medium severity vulnerability CVE-2024-13561 was detected. This vulnerability allows attackers to inject arbitrary web scripts via the brid_override_yt shortcode, leading to stored cross-site scripting (XSS). To address this issue, users should upgrade Target Video Easy Publish plugin for WordPress to version 3.8.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13561.
Read more CMS