In Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 a medium severity vulnerability CVE-2024-54083 was detected. This vulnerability allows attackers to cause a client-side denial of service (DoS) to users of particular channels by sending specially crafted posts. To address this issue, users should upgrade Mattermost to version 10.1.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-54083.
Read more CommunicationIn Vaultwarden versions 1.32.6 and prior a high severity vulnerability CVE-2024-56335 was detected. This vulnerability allows attackers with specific conditions to update or delete groups from an organization, potentially causing denial of service or privilege escalation. No patched version has been officially released at this time. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-56335.
Read more SecurityIn WooCommerce Point of Sale plugin for WordPress versions up to 6.1.0 a critical severity vulnerability CVE-2024-11281 was detected. This vulnerability allows attackers to change the email and reset the password of any user, including administrators, due to insufficient validation of the ‘logged_in_user_id’ value. To address this issue, users should upgrade to version 6.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11281.
Read more E-commerceIn GitLab versions before 17.6.0 a low severity vulnerability CVE-2023-5117 was detected. This vulnerability allows attackers to access files uploaded to comments on confidential issues and epics of public projects without authentication via a direct link to the uploaded file URL. To address this issue, users should upgrade to version 17.6.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-5117.
Read more Developer ToolsIn WPForms WordPress plugin versions prior to 1.9.2.3 a medium severity vulnerability CVE-2024-11223 was detected. This vulnerability allows high-privilege users, such as administrators, to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disabled (e.g., in multisite setups). To address this issue, users should upgrade to version 1.9.2.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11223.
Read more CMSIn Broken Link Checker WordPress plugin versions prior to 2.4.2 a high severity vulnerability CVE-2024-10903 was detected. This vulnerability allows admin users to perform Server-Side Request Forgery (SSRF) attacks by exploiting unvalidated link URLs, potentially compromising multisite installations. To address this issue, users should upgrade to version 2.4.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10903.
Read more CMSIn the Avada (Fusion) Builder plugin for WordPress versions up to 3.11.12 a medium severity vulnerability CVE-2024-12335 was detected. This vulnerability allows attackers with contributor-level access or higher to access sensitive information from protected, private, or draft posts in WordPress. To fix this issue, users should upgrade Avada (Fusion) Builder plugin for WordPress to version 3.11.13. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-12335.
Read more CMSIn Gogs versions prior to 0.13.1 a high severity vulnerability CVE-2024-55947 was detected. This vulnerability allows attackers to create files in any location on the server, which can lead to unauthorized SSH access. To address this issue, users should upgrade Gogs to version 0.13.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-55947.
Read more Developer ToolsIn Gogs versions prior to 0.13.1 a critical severity vulnerability CVE-2024-54148 was detected. This vulnerability allows attackers to commit and edit a crafted symlink file in a repository to gain unauthorized SSH access to the server. To address this issue, users should upgrade Gogs to version 0.13.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-54148.
Read more Developer Tools