Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High0
Medium4
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2024-11-21

CVE-2024-2234 - Himer Theme

The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks

THEME Himer

CVE-2024-2234

MEDIUM CVSS 5.4 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2235 - Himer Theme

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, including those they don't have access to via a CSRF attack

THEME Himer

CVE-2024-2235

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2233 - Himer Theme

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group invitations or leaving a group

THEME Himer

CVE-2024-2233

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2040 - Himer Theme

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users join private groups via a CSRF attack

THEME Himer

CVE-2024-2040

MEDIUM CVSS 4.3 2024-07-03
Scroll to top