In Directus versions before 10.11.2 a high severity vulnerability CVE-2024-36128 was detected. This vulnerability allows attackers to cause a denial of service by providing a non-numeric length value to the random string generation utility, breaking the ability to generate random strings and affecting session refresh functionality. To address this issue, users should upgrade to version 10.11.2 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36128.
Read more CMSIn Directus versions before 10.12.0 a medium severity vulnerability CVE-2024-39895 was detected. This vulnerability allows attackers to perform a denial of service (DoS) attack by sending GraphQL queries with duplicated fields, causing excessive resource consumption and impacting legitimate users. To address this issue, users should upgrade to version 10.12.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39895.
Read more CMSIn Nextcloud Server and Enterprise Server versions from 25.0.0 to 30.0.1 a medium severity vulnerability CVE-2024-52517 was detected. This vulnerability allows attackers with access to an active user session to read global credentials in plain text. To address this issue, users should upgrade to Nextcloud Server versions 28.0.11, 29.0.8, or 30.0.1 and Nextcloud Enterprise Server versions 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8, or 30.0.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52517.
Read more StorageIn Directus versions before 10.13.2 a medium severity vulnerability CVE-2024-47822 was detected. This vulnerability allows attackers to gain unauthorized data access and manipulation by exploiting exposed access tokens in system logs. To address this issue, users should upgrade to version 10.13.2 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-47822.
Read more CMSIn Kanboard versions 1.2.48 and below a critical severity vulnerability CVE-2026-21881 was detected. This vulnerability allows attackers to bypass authentication and impersonate any user, including administrators, by sending spoofed HTTP headers when REVERSE_PROXY_AUTH is enabled, as the application does not verify that requests originate from a trusted reverse proxy. To address this issue, users should upgrade Kanboard to version 1.2.49. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21881.
Read more Project ManagementIn Kanboard versions 1.2.48 and below a medium severity vulnerability CVE-2026-21880 was detected. This vulnerability allows attackers to exploit improper input sanitization in the LDAP authentication mechanism to perform LDAP injection, enabling user enumeration and disclosure of sensitive LDAP user attributes. To address this issue, users should upgrade Kanboard to version 1.2.49. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21880.
Read more Project ManagementIn WP Job Portal WordPress plugin versions up to and including 2.2.4 a medium severity vulnerability CVE-2024-12132 was detected. This vulnerability allows authenticated attackers with Subscriber-level access or higher to create jobs for companies they are not affiliated with due to missing validation on a user-controlled key. To address this issue, users should upgrade to a version 2.2.5 or above. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12132.
Read more CMSIn wp-enable-svg WordPress plugin through version 0.7 a medium severity vulnerability CVE-2024-11184 was detected. This vulnerability allows authors and higher-privileged users to upload SVG files containing malicious scripts due to insufficient sanitization during file uploads. No patched version has been officially released at this time. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11184.
Read more CMSIn goodlayers-core WordPress plugin before version 2.0.10 a medium severity vulnerability CVE-2024-11357 was detected. This vulnerability allows users with the contributor role or higher to perform Stored Cross-Site Scripting (XSS) attacks by exploiting unsanitized and unescaped settings. To address this issue, users should upgrade to version 2.0.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11357.
Read more CMS