Show filters
36 Total Results
Displaying 1-10 of 36
Sort by:
Attacker Value
Moderate

CVE-2021-23758

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
Attacker Value
Unknown

CVE-2023-33493

Disclosure Date: August 01, 2023 (last updated February 25, 2025)
An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions.
Attacker Value
Unknown

CVE-2023-1435

Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-1420

Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-2027

Disclosure Date: April 15, 2023 (last updated February 24, 2025)
The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.
Attacker Value
Unknown

CVE-2022-38456

Disclosure Date: March 15, 2023 (last updated February 24, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.
Attacker Value
Unknown

CVE-2008-10002

Disclosure Date: March 05, 2023 (last updated February 24, 2025)
A vulnerability has been found in cfire24 ajaxlife up to 0.3.2 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 0.3.3 is able to address this issue. The patch is identified as 9fb53b67312fe3f4336e01c1e3e1bedb4be0c1c8. It is recommended to upgrade the affected component. VDB-222286 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-40358

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafted svg file upload.
Attacker Value
Unknown

CVE-2022-1749

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.
Attacker Value
Unknown

CVE-2021-41472

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.