Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-05-15

CVE-2024-5029 - Cm Table Of Contents Plugin

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

PLUGIN Cm Table Of Contents

CVE-2024-5029

MEDIUM CVSS 4.8 2024-11-21
Threat Entry Updated 2025-05-15

CVE-2024-5030 - Cm Table Of Contents Plugin

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

PLUGIN Cm Table Of Contents

CVE-2024-5030

LOW CVSS 3.8 2024-11-18
Scroll to top