CVE-2024-37199

WordPress Enfold theme <= 5.6.9 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kriesi.At Enfold allows Reflected XSS.This issue affects Enfold: from n/a through 5.6.9.


We have discovered 118,598 live websites that are affected by CVE-2024-37199.

Test my site




Affected Software

Product  Enfold
Category Wordpress Themes
Vulnerable Domains118,598 live websites (68.57% of Enfold install base)
Vulnerable Versions
  • from 0 through 5.6.9
Vulnerable Versions Count208 versions ( 76.75% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 22, 2024
  • Updated - Aug 2, 2024

Credits

  • tom (Patchstack Alliance) (finder)

CVE-2024-37199 usage by Country

United States33,338 websites



Germany25,621 websites
Netherlands7,168 websites
France6,688 websites
GB4,202 websites
Italy3,725 websites
Spain3,415 websites
Denmark2,712 websites
Switzerland2,422 websites
Australia1,961 websites

CVE-2024-37199 usage by TLD

.com42,475 websites
.de16,517 websites
.nl7,389 websites
.org4,389 websites
.co.uk3,416 websites
.it3,240 websites
.fr2,524 websites
.at2,484 websites
.com.au2,207 websites
.net2,134 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-37199

Top websites that are affected by CVE-2024-37199. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com United States*,***
********.net United States**,***
************.com United States**,***
********.com Austria**,***
*****************************.de Germany**,***
*******.com Germany**,***
*********.com United States**,***
********************.***.uk United States**,***
**************.org United States**,***
**************.fr France**,***
See full domain list

FAQ

CVE-2024-37199 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Enfold
A total of 118,598 websites have been identified as vulnerable to CVE-2024-37199, discovered through global website indexing conducted by WebTechSurvey.
Enfold is susceptible to CVE-2024-37199 vulnerability.
Enfold versions before, and including, 5.6.9 are vulnerable to CVE-2024-37199.