scriptonite CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

scriptonite vulnerability overview

Aggregates CVE and security vulnerability intelligence across all scriptonite-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk csrf and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-6019 The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators [email protected] 6.1 0.33% 2024-09-12 2024-09-13
CVE-2024-6018 The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers [email protected] 6.1 0.30% 2024-09-12 2024-09-13
CVE-2024-6017 The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack [email protected] 6.1 0.18% 2024-09-12 2024-09-13
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence