Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown
CVE-2023-25026
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in PayPal PayPal Brasil para WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Brasil para WooCommerce: from n/a through 1.4.2.
0
Attacker Value
Unknown
CVE-2023-27460
Disclosure Date: June 03, 2024 (last updated June 04, 2024)
Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34.
0
Attacker Value
Unknown
CVE-2023-23785
Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DgCult Exquisite PayPal Donation plugin <= v2.0.0 versions.
0
Attacker Value
Unknown
CVE-2023-0535
Disclosure Date: February 27, 2023 (last updated October 08, 2023)
The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2022-48345
Disclosure Date: February 24, 2023 (last updated October 08, 2023)
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
0
Attacker Value
Unknown
CVE-2022-21129
Disclosure Date: January 31, 2023 (last updated November 08, 2023)
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function.
**Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.
0
Attacker Value
Unknown
CVE-2021-23648
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
0
Attacker Value
Unknown
CVE-2017-6217
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
0
Attacker Value
Unknown
CVE-2017-6215
Disclosure Date: August 02, 2018 (last updated November 27, 2024)
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.
0
Attacker Value
Unknown
CVE-2017-6213
Disclosure Date: August 02, 2018 (last updated November 27, 2024)
paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.
0