In GitLab CE/EE versions 10.6 up to 16.9.7, 16.10 up to 16.10.5, and 16.11 up to 16.11.2 a medium severity vulnerability CVE-2024-1211 was detected. This vulnerability allows attackers to potentially exploit cross-site request forgery (CSRF) on GitLab instances configured to use JWT as an OmniAuth provider. To address this issue, users should upgrade GitLab CE/EE to versions 16.11.2, 16.10.5 or 16.9.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-1211.
Read more Developer ToolsIn GitLab CE/EE versions 15.5 up to 16.9.7, 16.10 up to 16.10.5, and 16.11 up to 16.11.2 a low severity vulnerability CVE-2023-6195 was detected. This vulnerability allows attackers to exploit server-side request forgery (SSRF) by using a malicious URL in the markdown image value when importing a GitHub repository. To address this issue, users should upgrade GitLab CE/EE to versions 16.11.2, 16.10.5 or 16.9.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-6195.
Read more Developer ToolsIn iTop version 16.0 a high severity vulnerability CVE-2024-53588 was detected. This vulnerability allows attackers to run malicious code on the system by tricking iTop VPN into loading a fake DLL file. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-53588.
In Elementor Website Builder Pro plugin for WordPress versions 3.25.10 and prior a medium severity vulnerability CVE-2024-8494 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to extract sensitive data, including the content of Private, Pending, and Draft Templates, via the `elementor-template` shortcode. To address this issue, users should upgrade Elementor Website Builder Pro plugin to version 3.25.11 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8494.
Read more CMSIn WP Image Uploader plugin for WordPress versions 1.0.1 and prior a high severity vulnerability CVE-2024-13720 was detected. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validation in the `gky_image_uploader_main_function()` function, potentially leading to remote code execution if critical files, such as`wp-config.php`, are deleted. To address this issue, users should upgrade to a patched version once available. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13720.
Read more CMS Business and Enterprise SolutionsIn StageShow plugin for WordPress versions 9.8.6 and prior a medium severity vulnerability CVE-2024-13705 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via improper escaping in the `remove_query_arg` function, potentially executing scripts when a user clicks on a malicious link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13705.
Read more CMS Business and Enterprise SolutionsIn ElementsKit Pro plugin for WordPress versions 3.7.8 and prior a medium severity vulnerability CVE-2025-0321 was detected. This vulnerability allows attackers with Contributor-level access and above to inject malicious web scripts via the ‘url’ parameter, leading to DOM-based stored cross-site scripting (XSS). To address this issue, users should upgrade ElementsKit Pro plugin to version 3.7.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0321.
Read more CMSIn MailUp Auto Subscription plugin for WordPress versions 1.1.0 and prior a medium severity vulnerability CVE-2024-13521 was detected. This vulnerability allows unauthenticated attackers to perform cross-site request forgery (CSRF) attacks, enabling them to update settings and inject malicious web scripts by tricking a site administrator into clicking a link. To address this issue, users should upgrade MailUp Auto Subscription plugin to version 1.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13521.
Read more CMSIn ThemeREX Addons plugin for WordPress versions 2.32.3 and prior a critical severity vulnerability CVE-2024-13448 was detected. This vulnerability allows unauthenticated attackers to upload arbitrary files to the affected site’s server, potentially enabling remote code execution. To address this issue, users should upgrade ThemeREX Addons plugin to version 2.34.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13448.
Read more CMS