Loading HuntDB...

automattic

33 Products 45 CVEs

CVE Severity Distribution (All Time)

Critical
3
High
9
Medium
29
Low
1

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 11 CVEs

Recent CVEs

View all
CVE-2024-37241 MEDIUM 8 months, 1 week ago

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager - Resume Manager allows Cross Site Request Forgery.This issue affects WP…

CVE-2024-37242 MEDIUM 8 months, 1 week ago

Cross-Site Request Forgery (CSRF) vulnerability in Automattic Newspack Newsletters allows Cross Site Request Forgery.This issue affects Newspack News…

CVE-2024-53900 CRITICAL 9 months, 1 week ago

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

CVE-2024-10486 MEDIUM 9 months, 3 weeks ago

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to p…

CVE-2024-9926 MEDIUM 10 months ago

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to …

CVE-2024-37423 HIGH 10 months, 1 week ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This…

CVE-2024-37425 MEDIUM 10 months, 1 week ago

Missing Authorization vulnerability in Automattic Newspack Blocks newspack-blocks allows Exploiting Incorrectly Configured Access Control Security Le…

CVE-2024-37443 MEDIUM 10 months, 1 week ago

Missing Authorization vulnerability in Automattic WP Job Manager - Resume Manager allows Exploiting Incorrectly Configured Access Control Security Le…

CVE-2024-37475 MEDIUM 10 months, 1 week ago

Missing Authorization vulnerability in Automattic Newspack Newsletters allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…

CVE-2024-37477 MEDIUM 10 months, 1 week ago

Missing Authorization vulnerability in Automattic Newspack Content Converter allows Exploiting Incorrectly Configured Access Control Security Levels.…