Wishlistmember
Wishlistmember Wishlist Member X: vulnerabilities and CVEs
Wishlistmember Wishlist Member X has 8 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months2
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57384 | Medium (6.5) | 0.22% | — | Jul 23, 2026 | Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. |
| CVE-2026-25445 | High (8.8) | 0.52% | — | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0. |
| CVE-2024-37108 | High (7.7) | 0.62% | — | Nov 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishList Member X allows Path Traversal.This issue affects WishList Member X: from n/a through 3.26.6. |
| CVE-2024-37106 | High (8.2) | 0.36% | — | Nov 1, 2024 | Missing Authorization vulnerability in WishList Products WishList Member X allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WishList Member X: from n/a through 3.26.6 |
| CVE-2024-37113 | Critical (9.8) | 0.54% | — | Jul 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. |
| CVE-2024-37110 | High (7.5) | 0.55% | — | Jul 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. |
| CVE-2024-37111 | High (7.5) | 0.46% | — | Jun 24, 2024 | Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. |
| CVE-2024-37107 | High (8.8) | 0.42% | — | Jun 24, 2024 | Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.