Web Application Detections Published in February 2025

Hitesh Kadu

In February, Qualys Web Application Scanning released QIDs targeting vulnerabilities in several widely used software products and frameworks, including, Bootstrap, CKEditor, DOMPurify, jQuery, SeaCMS, Cacti, WordPress, Devika AI, YesWiki, YouDian CMS, Zimbra, Ollama, Adobe Magento, Roundcube Webmail, Flowise, Cockpit, ClassCMS, LiteLLM, Nginx UI, Backdrop CMS, Prometheus, Apache Ambari, Ivanti Cloud Services Application (CSA), Ivanti Connect Secure (ICS), GraphQL, Fortinet FortiOS, GitLab CE/EE, Progress Telerik Report Server, Trimble Cityworks, JetBrains TeamCity, Palo Alto Networks PAN-OS, Werkzeug, Apache OFBiz, Kibana, XWiki, Craft CMS, Mattermost

The QIDs released to detect the vulnerabilities in the frameworks above are listed below, details about the following QIDs can be found in our knowledge base. Please review reports of the scanned applications for these detections and, if any are identified, follow the steps provided in the knowledge base to ensure applications are protected against the reported vulnerabilities. Resolution of these vulnerabilities as soon as they are detected should be a priority for all organizations. These vulnerabilities can pose security risks if not addressed. Security risks can include breaches, unauthorized access, and various malicious activities.

QIDTitle
151043Bootstrap Cross-Site Scripting (XSS) Vulnerability (CVE-2024-6485)
151044Bootstrap Cross-Site Scripting (XSS) Vulnerability (CVE-2024-6484)
151045CKEditor Cross-Site Scripting (XSS) Vulnerability (CVE-2024-43407)
151046CKEditor Cross-Site Scripting (XSS) Vulnerability (CVE-2024-43411)
151047CKEditor Cross-Site Scripting (XSS) Vulnerability (CVE-2024-24815)
151048CKEditor Cross-Site Scripting (XSS) Vulnerability (CVE-2024-24816)
151049DOMPurify Prototype Pollution Vulnerability (CVE-2024-48910)
151050DOMPurify Cross-Site Scripting (XSS) Vulnerability (CVE-2024-47875)
151051jQuery Cross-Site Scripting (XSS) Vulnerability (CVE-2020-11023)
152687SeaCMS Incorrect Access Control Vulnerability (CVE-2024-54879)
152697Cacti Remote Code Execution (RCE) Vulnerabilities (CVE-2025-22604,CVE-2025-24367)
152698Cacti SQL Injection Vulnerabilities (CVE-2024-54145,CVE-2024-54146)
152699Cacti SQL Injection Vulnerability (CVE-2025-24368)
152700Cacti Local File Inclusion (LFI) Vulnerability (CVE-2024-45598)
152701WordPress Premium Packages Plugin: SQL Injection Vulnerability (CVE-2025-24659)
152702WordPress Shipping for Nova Poshta Plugin: SQL Injection Vulnerability (CVE-2025-24612)
152703Devika AI Local File Inclusion (LFI) Vulnerability (CVE-2024-5334)
152704WordPress iControlWP Plugin: PHP Object Injection Vulnerability (CVE-2024-13742)
152705YesWiki DOM-based Cross-site Scripting (XSS) Vulnerability (CVE-2025-24017)
152706WordPress WooCommerce Wishlist Plugin: Insecure Direct Object Reference Vulnerability (CVE-2024-13694)
152707Devika AI Path Traversal Vulnerability (CVE-2024-40422)
152708WordPress Bulk Me Now Plugin: Reflected Cross Site Scripting Vulnerability (CVE-2024-12638)
152709WordPress Flexible Wishlist for WooCommerce Plugin: Stored Cross Site Scripting Vulnerability (CVE-2024-13696)
152710WordPress Single-user-chat Plugin: Unauthorized Modification of Data Vulnerability (CVE-2024-13646)
152711WordPress MWB HubSpot for WooCommerce Plugin: Unauthorized Modification of Data Vulnerability (CVE-2024-10591)
152712YouDian CMS Session ID Privilege Escalation Vulnerability (CVE-2024-57052)
152713Zimbra SQL Injection Vulnerability (CVE-2025-25064)
152714Zimbra Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-25065)
152715WordPress MultiVendorX Plugin: Local File Inclusion Vulnerability (CVE-2025-0493)
152716Ollama Multiple Denial of Service Vulnerabilities
152717WordPress JupiterX Core Plugin: Local File Inclusion Vulnerability (CVE-2025-0366)
152718Adobe Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-49521)
152719WordPress ELEX WordPress HelpDesk and Customer Ticketing System Plugin: Privilege Escalation Vulnerability (CVE-2024-12171)
152720Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability (CVE-2024-57004)
152721WordPress Post/Page Copying Tool Plugin: Code Injection Vulnerability (CVE-2025-24677)
152722Flowise Authentication Bypass vulnerability (CVE-2024-8181)
152723Cockpit – Content Platform Arbitrary File Upload Vulnerability (CVE-2025-1025)
152724WordPress VikBooking Plugin: Cross-Site Request Forgery Vulnerability (CVE-2024-11641)
152725WordPress WP Image Uploader Plugin: Arbitrary File Deletion Vulnerability (CVE-2024-13720)
152726WordPress WP Image Uploader Plugin: Cross-Site Request Forgery Vulnerability (CVE-2024-13707)
152728ClassCMS Code Execution Vulnerability (CVE-2024-57099)
152729Ollama Model Detected
152730LiteLLM Information Disclosure Vulnerability (CVE-2025-0330)
152731WordPress Taxi Booking Manager for WooCommerce Plugin: PHP Object Injection Vulnerability (CVE-2025-24661)
152732Nginx UI Arbitrary Command Execution Vulnerability (CVE-2024-49368)
152733WordPress Contact Manager Plugin: Arbitrary File Upload Vulnerability (CVE-2025-1028)
152734Backdrop CMS Stored Cross-Site-Scripting (XSS) Vulnerability (CVE-2025-25062)
152735Backdrop CMS SVG Cross-Site-Scripting (XSS) Vulnerability (CVE-2025-25063)
152736Prometheus Metrics Detected
152737Prometheus Config Detected
152738Prometheus Targets Detected
152739Prometheus Flags Detected
152740WordPress Solidres – Hotel Booking Plugin: Reflected Cross-Site Scripting Vulnerability (CVE-2024-13329)
152741WordPress Justrows Free Plugin: Reflected Cross-Site Scripting Vulnerability (CVE-2024-13330)
152742Apache Ambari Remote Code Injection Vulnerability (CVE-2024-51941)
152743Apache Ambari XML External Entity (XXE) Vulnerability (CVE-2025-23195)
152744Ivanti Cloud Services Application (CSA) OS Command Injection Vulnerability (CVE-2024-47908)
152745Ivanti Cloud Services Application (CSA) Path Traversal Vulnerability (CVE-2024-11771)
152746Adobe Magento Multiple Vulnerabilities (APSB25-08)
152747Ivanti Connect Secure (ICS) Arbitrary File Write Vulnerability (CVE-2024-38657)
152748Ivanti Connect Secure (ICS) Stack-based Buffer Overflow Vulnerability (CVE-2025-22467)
152749Ivanti Connect Secure (ICS) Code injection Vulnerability (CVE-2024-10644)
152750GraphQL Field Suggestions
152751Fortinet FortiOS Authentication Bypass Vulnerability (CVE-2025-24472)
152752Ivanti Connect Secure (ICS) Arbitrary File Read Vulnerability (CVE-2024-12058)
152756WordPress All-Images.ai Plugin: Arbitrary File Upload Vulnerability (CVE-2024-13714)
152757GitLab CE/EE Unauthorized Pipeline Triggering Vulnerability (CVE-2024-7102)
152758GitLab CE/EE Cross-Site Scripting (XSS) Vulnerability (CVE-2025-0376)
152760Progress Telerik Report Server Cleartext Transmission of Sensitive Information Vulnerability (CVE-2025-0556)
152761Ivanti Connect Secure (ICS) Reflected XSS Vulnerability (CVE-2024-13830)
152762Ivanti Connect Secure (ICS) Hardcoded Key Vulnerability (CVE-2024-13842)
152763Ivanti Connect Secure (ICS) Sensitive Information Disclosure Vulnerability (CVE-2024-13843)
152764WordPress Security and Malware scan by CleanTalk Plugin: Arbitrary File Upload Vulnerability (CVE-2024-13365)
152765GitLab CE/EE Denial of Service (DoS) Vulnerability (CVE-2024-9631)
152766Trimble Cityworks Insecure Deserialization Vulnerability (CVE-2025-0994)
152767WordPress Brizy – Page Builder Plugin: Arbitrary File Upload Vulnerability (CVE-2024-10960)
152768WordPress Keap Official Opt-in Forms Plugin: Local File Inclusion Vulnerability (CVE-2024-13725)
152769WordPress Option Editor Plugin: Cross-Site Request Forgery Vulnerability (CVE-2024-13852)
152770WordPress LTL Freight Quotes – FreightQuote Edition Plugin: SQL Injection Vulnerability (CVE-2025-22290)
152771JetBrains TeamCity Sensitive Resource Exposure Vulnerability (CVE-2025-26492)
152772JetBrains TeamCity DOM-based Cross-Site Scripting (XSS) Vulnerability (CVE-2025-26493)
152773WordPress Shared Files Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2024-13504)
152774WordPress Permalink Finder Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2025-0809)
152775Palo Alto Networks PAN-OS Authentication Bypass Vulnerability (CVE-2025-0108)
152776Werkzeug Remote Code Execution (RCE) Vulnerability (CVE-2024-34069)
152777Werkzeug Path Traversal Vulnerability (CVE-2024-49766)
152778Werkzeug File Parsing Resource Exhaustion Vulnerability (CVE-2024-49767)
152779Apache OFBiz Forced Browsing Vulnerability (CVE-2024-45195)
152780Kibana Server-Side Request Forgery Vulnerability (CVE-2024-43710)
152781Kibana Server-Side Request Forgery Vulnerability (CVE-2024-43707)
152782XWiki Remote Code Execution (RCE) Vulnerability (CVE-2025-24893)
152783Craft CMS Remote Code Execution (RCE) Vulnerability (CVE-2025-23209)
152784Mattermost Multiple Path Traversal Vulnerabilities (CVE-2025-25279,CVE-2025-20051)
152785Mattermost SQL Injection Vulnerability (CVE-2025-24490)
152787WordPress Simplified Plugin: Arbitrary File Upload Vulnerability (CVE-2025-22654)
152788Apache Ambari Code Injection Vulnerability (CVE-2025-23196)
152790WordPress Ravpage Plugin: PHP Object Injection Vulnerability (CVE-2024-13789)
152792WordPress Responsive Addons for Elementor Plugin: Local File Inclusion Vulnerability (CVE-2024-13353)
152793WordPress GetBookingsWp Plugin: Privilege Escalation Vulnerability (CVE-2024-13677)
Share your Comments

Comments

Your email address will not be published. Required fields are marked *