Vulnerabilities (CVE)

Filtered by vendor Automattic Subscribe
Total 64 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-2009 1 Automattic 1 Wp Super Cache 2024-11-21 6.8 MEDIUM 8.8 HIGH
WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
CVE-2013-2008 1 Automattic 1 Wp Super Cache 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
WordPress Super Cache Plugin 1.3 has XSS.
CVE-2024-7786 1 Automattic 1 Sensei Lms 2024-10-07 N/A 5.3 MEDIUM
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
CVE-2024-43949 1 Automattic 2 Ghacitivity, Ghactivity 2024-09-03 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through 2.0.0-alpha.