Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kslatz

#19067of 53,625
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2024-36262
7.5
2024-12-16
Spider Themes · Eazydocs · CVE-2024-54376
Name of the Vulnerable Software and Affected Versions: EazyDocs versions prior to 2.5.5 Description: The issue is related to improper control of filename for Include/Require Statement in PHP Program, also known as 'PHP Remote File Inclusion'. This problem affects Spider-themes EazyDocs. Recommendations: For versions prior to 2.5.5, update to version 2.5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Include/Require Statement functionality until a patch is available.
PT-2024-32601
6.5
2024-10-05
Unknown · Webvitaly Page-List · CVE-2024-47382
**Name of the Vulnerable Software and Affected Versions** Webvitaly Page-list versions n/a through 5.6 **Description** The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows for Stored XSS attacks. The vulnerability is due to the improper neutralization of input when generating web pages. **Recommendations** For versions n/a through 5.6, update to a version that properly neutralizes input during web page generation to prevent Stored XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.