
cve2024-49740
cve2024-49740

cve2024-49740
WBCE CMS 1.6.1 is affected by a cross-site stored scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a payload crafted…

Cockpit CMS 2.7.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

WSO2-2021-1261: Multiple Cross-Site Scripting in WSO2 ESB

WSO2-2021-1260: Deletion of Arbitrary files via Path Traversal in Artifact Name in WSO2 ESB

WSO2-2021-1258: Zip Slip vulnerability in WSO2 ESB

MAL-005: Zip Slip in Add Carbon Applications in WSO2 ESB

RCE-POC-RealEstate CMS


JS Job Manager < 1.1.9 - Unauthenticated Arbitrary Plugin Installation/Activation

e-signature < 1.5.6.8 - Unauthenticated Remote Code Execution

Appsplate <= 2.1.3 - Unauthenticated SQL Injection

Popup – MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Unauthenticated SQL Injection

Astra Pro Addon < 3.5.2 - Unauthenticated SQL Injection - CVE-2021-24507

Share Buttons – Social Media <= 1.0.2 - Unauthenticated SQL Injection

Nabz Image Gallery <= v1.00 - Unauthenticated SQL Injection

eTemplates <= 0.2.1 - Unauthenticated SQL Injection

Radio Player <= 2.0.82 - Blind Unauthenticated Server-Side Request Forgery