<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Bootstrap</title>
  <link>https://cvedaily.com/pages/tags/bootstrap.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/bootstrap.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Bootstrap</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:36 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-44825 – Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44825</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44825</strong></p>
  <p>Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.   As an immediate workaround without upgrading, delete the template users (superadmin, a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32905 – OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32905</guid>
    <pubDate>Fri, 29 May 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32905</strong></p>
  <p>OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45021 – Kuma is a modern Envoy-based service mesh that can run on every cloud across bot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45021</guid>
    <pubDate>Thu, 28 May 2026 18:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45021</strong></p>
  <p>Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. CorsAllowedDomains: [".*"] reflects any Origin, and LocalhostIsAdmin: true…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45055 – CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45055</guid>
    <pubDate>Wed, 13 May 2026 21:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45055</strong></p>
  <p>CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset link in User::passwordRequest() (and the admin equivalent in Admin::passwordRequest()). An unauthenticated attacker who know…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7661 – The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7661</guid>
    <pubDate>Tue, 12 May 2026 09:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7661</strong></p>
  <p>The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will ex…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44994 – OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44994</guid>
    <pubDate>Mon, 11 May 2026 18:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44994</strong></p>
  <p>OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated attackers to read sensitive configuration fields. Attackers can access the bootstrap config route without a valid Gateway token to expose sensitive bootstrap and config information intended only for authenticated Control UI sessions.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42222 – Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42222</guid>
    <pubDate>Mon, 04 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42222</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7508 – A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7508</guid>
    <pubDate>Thu, 30 Apr 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7508</strong></p>
  <p>A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The code repository of the project has not been a…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41387 – OpenClaw before 2026.3.22 contains an incomplete host environment variable sanit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41387</guid>
    <pubDate>Tue, 28 Apr 2026 19:37:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41387</strong></p>
  <p>OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package-manager environment overrides. Attackers can exploit approved exec requests to redirect package resolution or runtime bootstrap to attacker-controlled infrastructure and execute trojanized content.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-183</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41386 – OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41386</guid>
    <pubDate>Tue, 28 Apr 2026 19:37:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41386</strong></p>
  <p>OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-648</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41335 – OpenClaw before 2026.3.31 contains an information disclosure vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41335</guid>
    <pubDate>Thu, 23 Apr 2026 22:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41335</strong></p>
  <p>OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that exposes version and assistant agent identifiers. Attackers can extract sensitive fingerprinting information from the Control UI bootstrap payload to identify system versions and agent configurations.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4117 – The CalJ plugin for WordPress is vulnerable to Missing Authorization in all vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4117</guid>
    <pubDate>Wed, 22 Apr 2026 09:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4117</strong></p>
  <p>The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability check in the CalJSettingsPage class constructor, which processes the 'save-obtained-key' operation directly from POST data without verifying that the requesting user has the 'manage_options' capability, and without any nonce verification. The plugin b…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4076 – The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4076</guid>
    <pubDate>Wed, 22 Apr 2026 09:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4076</strong></p>
  <p>The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and 'template' shortcode attributes in all versions up to and including 1.0.7. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The plugin uses extract() on shortcode_atts() to parse attributes, then directly outputs the $categ…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40518 – ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40518</guid>
    <pubDate>Fri, 17 Apr 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40518</strong></p>
  <p>ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply traversal-style values or absolute paths as the agent name to influence directory creation and write files outside the intended custom-agent directory, potentially achieving arbitrary fil…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6507 – A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds wr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6507</guid>
    <pubDate>Fri, 17 Apr 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6507</strong></p>
  <p>A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40044 – Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40044</guid>
    <pubDate>Mon, 13 Apr 2026 19:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40044</strong></p>
  <p>Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files with predictable names in the cache directory, which are unserialized during framework bootstrap before authentication checks occur.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31940 – Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31940</guid>
    <pubDate>Fri, 10 Apr 2026 18:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31940</strong></p>
  <p>Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5412 – In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5412</guid>
    <pubDate>Fri, 10 Apr 2026 13:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5412</strong></p>
  <p>In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4482 – The installer certificate files in the …/bootstrap/common/ssl folder do not seem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4482</guid>
    <pubDate>Fri, 10 Apr 2026 05:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4482</strong></p>
  <p>The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32712 – Open Source Point of Sale is a web based point-of-sale application written in PH...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32712</guid>
    <pubDate>Tue, 07 Apr 2026 21:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32712</strong></p>
  <p>Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer_name column is configured with escape: false in the bootstrap-table column configuration, causing customer names to be rendered as raw HTML. An attacker with custome…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32987 – OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during dev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32987</guid>
    <pubDate>Sun, 29 Mar 2026 13:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32987</strong></p>
  <p>OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, including privilege escalation to operator.admin.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1307 – The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1307</guid>
    <pubDate>Sat, 28 Mar 2026 07:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1307</strong></p>
  <p>The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain access to an authorization…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34386 – Fleet is open source device management software. Prior to 4.81.0, a SQL injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34386</guid>
    <pubDate>Fri, 27 Mar 2026 19:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34386</strong></p>
  <p>Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurations, exfiltrate sensitive data from the Fleet database, and inject arbitrary content into team configs via direct API calls. Version 4.81.0 patches…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32041 – OpenClaw versions prior to 2026.3.1 fail to properly handle authentication boots...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32041</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32041</strong></p>
  <p>OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can exploit this to access browser-control routes including evaluate-capable actions without valid credentials.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31957 – Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31957</guid>
    <pubDate>Wed, 11 Mar 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31957</strong></p>
  <p>Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentication is not tenant-scoped. In this mode, Himmelblau can accept authentication attempts for arbitrary Entra ID domains by dynamically registering providers at runtime. This behavior is intended for in…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27009 – OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27009</guid>
    <pubDate>Fri, 20 Feb 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27009</strong></p>
  <p>OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (name/avatar) into an inline `<script>` tag without script-context-safe escaping. A crafted value containing `</script>` could break out of the script tag and execute attacker-controlled JavaScript in the Control UI origin. Version 2026.2.15 removed inli…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25791 – Sliver is a command and control framework that uses a custom Wireguard netstack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25791</guid>
    <pubDate>Mon, 09 Feb 2026 21:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25791</strong></p>
  <p>Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because sessions are stored without a cleanup/expiry path in this flow, an unauthenticated remote actor can repeatedly create sessi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62095 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62095</guid>
    <pubDate>Wed, 31 Dec 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62095</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in neilgee Bootstrap Modals bootstrap-modals allows Stored XSS.This issue affects Bootstrap Modals: from n/a through <= 1.3.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63387 – Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63387</guid>
    <pubDate>Thu, 18 Dec 2025 19:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63387</strong></p>
  <p>Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unaut…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-63386 – A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63386</guid>
    <pubDate>Thu, 18 Dec 2025 16:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-63386</strong></p>
  <p>A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. NOTE: the Supplier disputes this because the endpoint configuration i…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11764 – The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11764</guid>
    <pubDate>Fri, 21 Nov 2025 08:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11764</strong></p>
  <p>The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the [notification] shortcode in all versions up to, and including, 1.1. This is due to missing input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will e…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11822 – The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Sc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11822</guid>
    <pubDate>Tue, 11 Nov 2025 04:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11822</strong></p>
  <p>The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcode in all versions up to, and including, 1.0.4. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11753 – The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11753</guid>
    <pubDate>Tue, 04 Nov 2025 05:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11753</strong></p>
  <p>The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whe…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8776 – The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8776</guid>
    <pubDate>Fri, 03 Oct 2025 12:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8776</strong></p>
  <p>The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9991 – The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9991</guid>
    <pubDate>Tue, 30 Sep 2025 11:37:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9991</strong></p>
  <p>The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive dat…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59052 – Angular is a development platform for building mobile and desktop web applicatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59052</guid>
    <pubDate>Wed, 10 Sep 2025 21:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59052</strong></p>
  <p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side rendering. For historical reasons, the container was stored as a JavaScript module-scoped global variable. When multiple requests are processed concurrently, they…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59042 – PyInstaller bundles a Python application and all its dependencies into a single ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59042</guid>
    <pubDate>Tue, 09 Sep 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59042</strong></p>
  <p>PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during the bootstrap process of a PyInstaller-frozen application, and due to the bootstrap script attempting to load an optional module for bytecode decryption while this entry is still present in `sys.path`, an application built with PyInstaller < 6.0.0 may…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41051 – A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41051</guid>
    <pubDate>Thu, 04 Sep 2025 12:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41051</strong></p>
  <p>A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/bootstrap.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54733 – Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54733</guid>
    <pubDate>Thu, 28 Aug 2025 13:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54733</strong></p>
  <p>Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.28.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8904 – Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8904</guid>
    <pubDate>Wed, 13 Aug 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8904</strong></p>
  <p>Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges.     Users are advised to upgrade to Amazon EMR version 7.5 or higher. For Amazon EMR releases between 6.10 and 7.4, we strongly recommend that you run…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-257</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6839 – A vulnerability, which was classified as critical, has been found in Conjure Pos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6839</guid>
    <pubDate>Sun, 29 Jun 2025 02:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6839</strong></p>
  <p>A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue is the function eval of the file public/assets/less/bootstrap-less/mixins/head.php. The manipulation of the argument payload leads to backdoor. The attack may be launched remotely. The exploit has been disclosed to the public and m…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-912</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30951 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30951</guid>
    <pubDate>Fri, 06 Jun 2025 13:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30951</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan BlockStrap Page Builder - Bootstrap Blocks blockstrap-page-builder-blocks allows Stored XSS.This issue affects BlockStrap Page Builder - Bootstrap Blocks: from n/a through <= 0.1.36.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-12722 – The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12722</guid>
    <pubDate>Thu, 15 May 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-12722</strong></p>
  <p>The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1647 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1647</guid>
    <pubDate>Thu, 15 May 2025 17:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1647</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47204 – An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Mult...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47204</guid>
    <pubDate>Tue, 13 May 2025 16:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47204</strong></p>
  <p>An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20155 – A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20155</guid>
    <pubDate>Wed, 07 May 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20155</strong></p>
  <p>A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system.  This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software when a device is first deployed in SD-WAN mode or when an administrator configures SD-Routing on the device. An attacker…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3901 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3901</guid>
    <pubDate>Wed, 23 Apr 2025 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3901</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32672 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32672</guid>
    <pubDate>Fri, 11 Apr 2025 09:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32672</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Ultimate Bootstrap Elements for Elementor ultimate-bootstrap-elements-for-elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through <= 1.4.9.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3060 – Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3060</guid>
    <pubDate>Mon, 31 Mar 2025 23:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3060</strong></p>
  <p>Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30527 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30527</guid>
    <pubDate>Mon, 24 Mar 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30527</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetoolbox My Bootstrap Menu my-bootstrap-menu allows Stored XSS.This issue affects My Bootstrap Menu: from n/a through <= 1.2.1.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27826 – An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Bac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27826</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27826</strong></p>
  <p>An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27825 – An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27825</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27825</strong></p>
  <p>An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-26551 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26551</guid>
    <pubDate>Thu, 13 Feb 2025 14:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-26551</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Bootstrap collapse bootstrap-collapse allows Stored XSS.This issue affects Bootstrap collapse: from n/a through <= 1.0.4.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13549 – The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13549</guid>
    <pubDate>Thu, 30 Jan 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13549</strong></p>
  <p>The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in all versions up to, and including, 1.3.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13545 – The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13545</guid>
    <pubDate>Fri, 24 Jan 2025 09:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13545</strong></p>
  <p>The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases wher…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24030 – Envoy Gateway is an open source project for managing Envoy Proxy as a standalone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24030</guid>
    <pubDate>Thu, 23 Jan 2025 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24030</strong></p>
  <p>Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy config…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-419</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22743 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22743</guid>
    <pubDate>Wed, 15 Jan 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22743</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohsin Rasool Twitter Bootstrap Collapse aka Accordian Shortcode twitter-bootstrap-collapse-aka-accordian-shortcode allows DOM-Based XSS.This issue affects Twitter Bootstrap Collapse aka Accordian Shortcode: from n/a through <= 1.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-12495 – The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12495</guid>
    <pubDate>Tue, 07 Jan 2025 07:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-12495</strong></p>
  <p>The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-bootstrap/column' block in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute wh…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49677 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49677</guid>
    <pubDate>Wed, 18 Dec 2024 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49677</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Cramer Bootstrap Buttons bootstrap-buttons allows Reflected XSS.This issue affects Bootstrap Buttons: from n/a through <= 1.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53824 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53824</guid>
    <pubDate>Fri, 06 Dec 2024 14:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53824</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows PHP Local File Inclusion.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.19.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11402 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11402</guid>
    <pubDate>Thu, 28 Nov 2024 11:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11402</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kubiq Block Editor Bootstrap Blocks block-editor-bootstrap-blocks allows Reflected XSS.This issue affects Block Editor Bootstrap Blocks: from n/a through <= 6.6.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51851 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51851</guid>
    <pubDate>Tue, 19 Nov 2024 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51851</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salehattari best bootstrap widgets for elementor best-bootstrap-widgets-for-elementor allows DOM-Based XSS.This issue affects best bootstrap widgets for elementor: from n/a through <= 1.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51810 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51810</guid>
    <pubDate>Tue, 19 Nov 2024 17:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51810</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Lewe Lewe Bootstrap Visuals shortcode-bootstrap-visuals allows Stored XSS.This issue affects Lewe Bootstrap Visuals: from n/a through <= 3.0.1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52583 – The WesHacks GitHub repository provides the official Hackathon competition websi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52583</guid>
    <pubDate>Mon, 18 Nov 2024 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52583</strong></p>
  <p>The WesHacks GitHub repository provides the official Hackathon competition website source code for the Muweilah Wesgreen Hackathon. The page `schedule.html` before 17 November 2024 or commit 93dfb83 contains links to `Leostop`, a site that hosts a malicious injected JavaScript file that occurs when bootstrap is run as well as jquery. `Leostop` may be a tracking malware and creates 2 JavaScript fi…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-50234 – In the Linux kernel, the following vulnerability has been resolved:

wifi: iwleg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50234</guid>
    <pubDate>Sat, 09 Nov 2024 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-50234</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: iwlegacy: Clear stale interrupts before resuming device  iwl4965 fails upon resume from hibernation on my laptop. The reason seems to be a stale interrupt which isn't being cleared out before interrupts are enabled. We end up with a race beween the resume trying to bring things back up, and the restart work (queued form th…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-10329 – The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10329</guid>
    <pubDate>Tue, 05 Nov 2024 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-10329</strong></p>
  <p>The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the 'ube_get_page_templates' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the contents of templates that are private.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-32189 – Insecure handling of ssh keys used to bootstrap clients allows local attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32189</guid>
    <pubDate>Wed, 16 Oct 2024 14:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-32189</strong></p>
  <p>Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6544 – The Custom Post Limits plugin for WordPress is vulnerable to full path disclosur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6544</guid>
    <pubDate>Fri, 13 Sep 2024 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6544</strong></p>
  <p>The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not use…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7415 – The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7415</guid>
    <pubDate>Fri, 06 Sep 2024 04:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7415</strong></p>
  <p>The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information display…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43349 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43349</guid>
    <pubDate>Sun, 18 Aug 2024 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43349</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.19.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43140 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43140</guid>
    <pubDate>Tue, 13 Aug 2024 12:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43140</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through 1.4.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7416 – The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7416</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7416</strong></p>
  <p>The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is n…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7413 – The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7413</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7413</strong></p>
  <p>The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7412 – The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7412</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7412</strong></p>
  <p>The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7382 – The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7382</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7382</strong></p>
  <p>The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6549 – The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6549</guid>
    <pubDate>Sat, 27 Jul 2024 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6549</strong></p>
  <p>The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not us…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6548 – The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6548</guid>
    <pubDate>Sat, 27 Jul 2024 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6548</strong></p>
  <p>The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not use…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6547 – The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6547</guid>
    <pubDate>Sat, 27 Jul 2024 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6547</strong></p>
  <p>The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1.  This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6546 – The One Click Close Comments plugin for WordPress is vulnerable to Full Path Dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6546</guid>
    <pubDate>Sat, 27 Jul 2024 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6546</strong></p>
  <p>The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is n…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6545 – The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6545</guid>
    <pubDate>Sat, 27 Jul 2024 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6545</strong></p>
  <p>The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not u…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7067 – A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f109...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7067</guid>
    <pubDate>Wed, 24 Jul 2024 14:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7067</strong></p>
  <p>A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. Affected by this issue is the function getCartProductsIds of the file app/Cart.php. The manipulation of the argument laraCart leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-40392 – SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40392</guid>
    <pubDate>Tue, 16 Jul 2024 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-40392</strong></p>
  <p>SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via the name parameter under addnew.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6485 – A security vulnerability has been discovered in bootstrap that could enable Cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6485</guid>
    <pubDate>Thu, 11 Jul 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6485</strong></p>
  <p>A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37462 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37462</guid>
    <pubDate>Tue, 09 Jul 2024 11:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37462</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows Path Traversal.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through 1.4.2.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-6526 – A vulnerability classified as problematic has been found in CodeIgniter Ecommerc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6526</guid>
    <pubDate>Fri, 05 Jul 2024 14:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-6526</strong></p>
  <p>A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37293 – The AWS Deployment Framework (ADF) is a framework to manage and deploy resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37293</guid>
    <pubDate>Tue, 11 Jun 2024 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37293</strong></p>
  <p>The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined in AWS Organizations while taking advantage of services such as AWS CodePipeline, AWS CodeBuild, and AWS CodeCommit to al…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35169 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35169</guid>
    <pubDate>Tue, 14 May 2024 15:39:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35169</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.15.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0847 – The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0847</guid>
    <pubDate>Thu, 02 May 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0847</strong></p>
  <p>The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in class-sbmm-list-table.php. This makes it possible for unauthenticated attackers to bulk delete messages via a forged request granted they can trick a site administrator into performing an action su…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31823 – An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31823</guid>
    <pubDate>Mon, 29 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31823</strong></p>
  <p>An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-31822 – An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31822</guid>
    <pubDate>Mon, 29 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-31822</strong></p>
  <p>An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31821 – SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31821</guid>
    <pubDate>Mon, 29 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31821</strong></p>
  <p>SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-31820 – An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31820</guid>
    <pubDate>Mon, 29 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-31820</strong></p>
  <p>An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31391 – Insertion of Sensitive Information into Log File vulnerability in the Apache Sol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31391</guid>
    <pubDate>Fri, 12 Apr 2024 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31391</strong></p>
  <p>Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator.  This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0.  When asked to bootstrap Solr security, the operator will enable basic authentication and create several accounts for accessing Solr: including the "solr" and "admin" accounts for use by end-users, and a "k8s-oper" accou…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-2132 – The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2132</guid>
    <pubDate>Sat, 06 Apr 2024 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-2132</strong></p>
  <p>The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Widget in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pag…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-1398 – The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1398</guid>
    <pubDate>Sat, 02 Mar 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-1398</strong></p>
  <p>The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_title_tag’ and ’heading_sub_title_tag’ parameters in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level and above permissions to inject arbitrary…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27294 – dp-golang is a Puppet module for Go installations.  Prior to 1.2.7, dp-golang co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27294</guid>
    <pubDate>Thu, 29 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27294</strong></p>
  <p>dp-golang is a Puppet module for Go installations.  Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 through 1.21rc3, inclusive, go1.4-bootstrap-20170518.tar.gz, or go1.4-bootstrap-20170531.tar.gz. The user and group specified in Puppet code were ignored for…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52196 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52196</guid>
    <pubDate>Mon, 08 Jan 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52196</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: from n/a through 1.12.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47851 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47851</guid>
    <pubDate>Thu, 30 Nov 2023 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47851</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akhtarujjaman Shuvo Bootstrap Shortcodes Ultimate allows Stored XSS.This issue affects Bootstrap Shortcodes Ultimate: from n/a through 4.3.1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40314 – Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40314</guid>
    <pubDate>Thu, 16 Nov 2023 22:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40314</strong></p>
  <p>Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Horizon 32.0.5 or newer and Meridian 2023.1.9 or newer           Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39417 – IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39417</guid>
    <pubDate>Fri, 11 Aug 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39417</strong></p>
  <p>IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39417">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
