Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SupportCandy allows Stored XSS.This issue affects SupportCandy: from n/a through 3.2.3.
We have discovered 428 live websites that are affected by CVE-2024-27991.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 428 live websites (21% of Supportcandy install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 32 versions ( 62% of all versions) |
| 96 websites | |
| 47 websites | |
| 36 websites | |
| 28 websites | |
| 23 websites | |
| 21 websites | |
| 20 websites | |
| 19 websites | |
| 13 websites | |
| 11 websites |
| .com | 155 websites |
| .it | 35 websites |
| .ru | 21 websites |
| .com.br | 19 websites |
| .net | 12 websites |
| .org | 12 websites |
| .de | 12 websites |
| .pl | 7 websites |
| .eu | 6 websites |
| .es | 6 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.app | **,*** | ||
| ****************.com | **,*** | ||
| ********.pt | **,*** | ||
| *****.sv | ***,*** | ||
| *****************.com | ***,*** | ||
| ***********.com | ***,*** | ||
| *********.com | ***,*** | ||
| *********.de | ***,*** | ||
| ************.***.au | ***,*** | ||
| ************.com | ***,*** |
FAQ