Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2024-50448
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-…
Yith Woocommerce Product Add Ons
4.14.2+
MEDIUM 5.4
CVE-2024-7846
YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it p…
Yith Woocommerce Ajax Search
2.7.1+
MEDIUM 6.1
CVE-2024-8665
The YITH Custom Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escapi…
Yith Custom Login
1.7.4+
MEDIUM 5.3
CVE-2024-35680
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocomm…
Yith Woocommerce Product Add Ons
4.9.3+
HIGH 8.8
CVE-2024-30470
Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/…
Woocommerce Account Funds
1.34.0+
MEDIUM 6.1
CVE-2024-4455
The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and in…
Yith Woocommerce Ajax Search
2.4.1+
HIGH 8.8
CVE-2023-49777
Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/…
Yith Woocommerce Product Add Ons
after 4.3.0
CRITICAL 9.8
CVE-2022-45359EPSS 14%
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
Yith Woocommerce Gift Cards
after 3.19.0
MEDIUM 6.1
CVE-2022-0818
The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a specific action handler, as well a…
Woocommerce Affiliate
4.16.4.5+
MEDIUM 5.4
CVE-2021-36841
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yi…
Yith Maintenance Mode
after 1.3.7
CRITICAL 9.8
CVE-2021-3120EPSS 37%
An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achiev…
Yith Woocommerce Gift Cards
3.3.1+
MEDIUM 6.5
CVE-2015-9429
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_…
Yith Maintenance Mode
1.2.0+