cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2021-24317,https://securityvulnerability.io/vulnerability/CVE-2021-24317,Listeo < 1.6.11 - Multiple XSS & XFS vulnerabilities,"The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues",Wordpress,Listeo,6.1,MEDIUM,0.0007600000244565308,false,,false,false,false,,false,false,2021-06-01T11:33:30.000Z,0 CVE-2021-24318,https://securityvulnerability.io/vulnerability/CVE-2021-24318,Listeo < 1.6.11 - Multiple Authenticated IDOR Vulnerabilities,"The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.",Wordpress,Listeo,6.5,MEDIUM,0.000590000010561198,false,,false,false,false,,false,false,2021-06-01T11:33:30.000Z,0