CWE-82 · 8 records
Improper Neutralization of Script in Attributes of IMG Tags in a Web Page
CVEs in this class
8 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2024-48042No exploit | WordPress Contact Form by Supsystic plugin <= 1.7.28 - Remote Code Execution (RCE) vulnerabilitysupsystic · contact form by supsystic · CWE-82 | Critical9.1 | — | 1.1% | Oct 16, 2024 |
36Monitor | CVE-2024-52434No exploit | WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerabilitysupsystic · popup · CWE-82 | Critical9.1 | — | 1.1% | Nov 18, 2024 |
35Monitor | CVE-2024-52427No exploit | WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerabilityvollstart · event tickets with ticket scanner · CWE-82 | High8.8 | — | 0.7% | Nov 18, 2024 |
34Monitor | CVE-2025-53194No exploit | WordPress JetEngine <= 3.7.0 - Remote Code Execution (RCE) Vulnerabilitycrocoblock · jetengine · CWE-82 | High8.5 | — | 0.4% | Aug 20, 2025 |
28Monitor | CVE-2024-49271No exploit | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-82 | High7.2 | — | 1.1% | Oct 16, 2024 |
28Monitor | CVE-2024-52393No exploit | WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerabilitypodlove · podlove podcast publisher · CWE-82 | High7.2 | — | 0.5% | Nov 14, 2024 |
21Monitor | CVE-2026-56735No exploit | Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammadzammad · zammad · CWE-82 | Medium5.3 | — | 0.4% | 5 days ago |
21Monitor | CVE-2023-30963No exploit | Stored XSS in Foundry Slate Query Dropdown menupalantir · foundry frontend · CWE-82 | Medium5.4 | — | 0.4% | Jul 10, 2023 |
- CVE-2024-4804236Monitor
WordPress Contact Form by Supsystic plugin <= 1.7.28 - Remote Code Execution (RCE) vulnerability
CriticalCVSS 9.1No exploitEPSS 1%supsystic · contact form by supsysticOct 16, 2024
- CVE-2024-5243436Monitor
WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerability
CriticalCVSS 9.1No exploitEPSS 1%supsystic · popupNov 18, 2024
- CVE-2024-5242735Monitor
WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerability
HighCVSS 8.8No exploitEPSS 1%vollstart · event tickets with ticket scannerNov 18, 2024
- CVE-2025-5319434Monitor
WordPress JetEngine <= 3.7.0 - Remote Code Execution (RCE) Vulnerability
HighCVSS 8.5No exploitEPSS 0%crocoblock · jetengineAug 20, 2025
- CVE-2024-4927128Monitor
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerability
HighCVSS 7.2No exploitEPSS 1%unlimited-elements · unlimited elements for elementorOct 16, 2024
- CVE-2024-5239328Monitor
WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability
HighCVSS 7.2No exploitEPSS 1%podlove · podlove podcast publisherNov 14, 2024
- CVE-2026-5673521Monitor
Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammad
MediumCVSS 5.3No exploitEPSS 0%zammad · zammad5 days ago
- CVE-2023-3096321Monitor
Stored XSS in Foundry Slate Query Dropdown menu
MediumCVSS 5.4No exploitEPSS 0%palantir · foundry frontendJul 10, 2023