In MagicForm plugin for WordPress versions 1.6.2 and prior a medium severity vulnerability CVE-2025-0939 was detected. This vulnerability allows authenticated attackers, with Subscriber-level access and above, to delete or view logs, modify forms, or change plugin settings due to missing capability checks on AJAX actions. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0939.
Read more CMS Business and Enterprise SolutionsIn Grafana versions prior to 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 and 10.4.15 a medium severity vulnerability CVE-2024-11741 was detected. This vulnerability allows users with Viewer permissions to improperly access the Grafana Alerting VictorOps integration. To address this issue, users should upgrade Grafana to versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 or 10.4.15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11741.
Read more Data AnalyticsIn Argo CD versions 2.13.4, 2.12.10 and 2.11.13 a medium severity vulnerability CVE-2025-23216 was detected.
This vulnerability allows attackers with write access to expose secret values in error messages and the diff view by syncing an invalid Kubernetes Secret, making them visible to any user with read access to Argo CD. To address this issue, users should upgrade Argo CD to version 2.13.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-23216.
In GitLab CE/EE versions 10.6 up to 16.9.7, 16.10 up to 16.10.5, and 16.11 up to 16.11.2 a medium severity vulnerability CVE-2024-1211 was detected. This vulnerability allows attackers to potentially exploit cross-site request forgery (CSRF) on GitLab instances configured to use JWT as an OmniAuth provider. To address this issue, users should upgrade GitLab CE/EE to versions 16.11.2, 16.10.5 or 16.9.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-1211.
Read more Developer ToolsIn The AI Infographic Maker plugin for WordPress versions 4.9.0 and prior a medium severity vulnerability CVE-2024-12415 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes due to improper validation of values before running do_shortcode. To address this issue, users should upgrade The AI Infographic Maker plugin to version 5.0.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12415.
Read more CMS Business and Enterprise SolutionsIn GitLab CE/EE versions 15.5 up to 16.9.7, 16.10 up to 16.10.5, and 16.11 up to 16.11.2 a low severity vulnerability CVE-2023-6195 was detected. This vulnerability allows attackers to exploit server-side request forgery (SSRF) by using a malicious URL in the markdown image value when importing a GitHub repository. To address this issue, users should upgrade GitLab CE/EE to versions 16.11.2, 16.10.5 or 16.9.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-6195.
Read more Developer ToolsIn WP DataTable plugin for WordPress versions 0.2.6 and prior a medium severity vulnerability CVE-2024-13566 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts via the ‘id’ parameter, leading to Stored Cross-Site Scripting. To address this issue, users should upgrade WP DataTable plugin to version 0.2.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13566.
Read more CMS Business and Enterprise SolutionsIn StageShow plugin for WordPress versions 9.8.6 and prior a medium severity vulnerability CVE-2024-13705 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via improper escaping in the `remove_query_arg` function, potentially executing scripts when a user clicks on a malicious link. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13705.
Read more CMS Business and Enterprise SolutionsIn iTop version 16.0 a high severity vulnerability CVE-2024-53588 was detected. This vulnerability allows attackers to run malicious code on the system by tricking iTop VPN into loading a fake DLL file. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-53588.