CVE-2024-37199

WordPress Enfold theme <= 5.6.9 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kriesi.At Enfold allows Reflected XSS.This issue affects Enfold: from n/a through 5.6.9.


We have discovered 96,570 live websites that are affected by CVE-2024-37199.

Run a Free Instant Scan




Affected Software

Product  Enfold
Category Wordpress Themes
Vulnerable Domains96,570 live websites (81% of Enfold install base)
Vulnerable Versions
  • from 0 through 5.6.9
Vulnerable Versions Count146 versions ( 78% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 22, 2024
  • Updated - Aug 2, 2024

Credits

  • tom (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2024-37199
United States22,081 websites



Germany19,420 websites
Netherlands6,460 websites
Italy5,406 websites
France4,799 websites
GB4,027 websites
Spain3,340 websites
Denmark2,065 websites
Austria1,933 websites
Switzerland1,860 websites

Website Distribution by TLD

Number of websites using CVE-2024-37199
.com34,000 websites
.de13,444 websites
.nl5,968 websites
.it3,877 websites
.org3,458 websites
.co.uk2,793 websites
.at2,055 websites
.fr1,998 websites
.net1,741 websites
.ch1,583 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-37199

Top websites that are affected by CVE-2024-37199. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com United States*,***
********.net United States**,***
************.com United States**,***
*****************************.de Germany**,***
*******.com Germany**,***
********************.***.uk GB**,***
**************.org United States**,***
**************.fr France**,***
*****.org United States**,***
*********.se United States**,***
See full domain list

FAQ

CVE-2024-37199 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Enfold
A total of 96,570 websites have been identified as vulnerable to CVE-2024-37199, based on global website indexing conducted by WebTechSurvey.
The Enfold is affected by the CVE-2024-37199 vulnerability.
Enfold versions up to and including 5.6.9 are vulnerable to CVE-2024-37199.