Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High1
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-11-13

CVE-2024-0852 - Coreactivity Plugin

The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin

PLUGIN Coreactivity

CVE-2024-0852

HIGH CVSS 8.8 2025-05-15
Threat Entry Updated 2025-06-17

CVE-2024-0868 - Coreactivity Plugin

The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value

PLUGIN Coreactivity

CVE-2024-0868

MEDIUM CVSS 5.3 2024-04-17
Scroll to top