Vulnerabilities
11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-33561 | Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-33555 | Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-33557 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue af Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-33556 +1 in the same advisory: …33552 | Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-33551 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5. NVD description · AI analysis pending | 9.8 group max | <1% |
| — |