Show filters
219 Total Results
Displaying 1-10 of 219
Sort by:
Attacker Value
Low

CVE-2018-15877

Disclosure Date: August 26, 2018 (last updated November 27, 2024)
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools request.
Attacker Value
Unknown

CVE-2023-37394

Disclosure Date: June 14, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0.
Attacker Value
Unknown

CVE-2023-31230

Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from n/a through 1.0.2.
Attacker Value
Unknown

CVE-2023-5918

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Visitor Management System 1.0. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-244308.
Attacker Value
Unknown

CVE-2023-5496

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A vulnerability was found in Translator PoqDev Add-On 1.0.11 on Firefox. It has been rated as problematic. This issue affects some unknown processing of the component Select Text Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-241649 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-40945

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
Attacker Value
Unknown

CVE-2023-34175

Disclosure Date: August 30, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.
Attacker Value
Unknown

CVE-2023-39852

Disclosure Date: August 15, 2023 (last updated February 25, 2025)
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that this originates from $_SESSION["userid"]=$_POST["userid"] at line 68 in doctors\doctorlogin.php, where userid under POST is not a session variable controlled by the server.
Attacker Value
Unknown

CVE-2023-34369

Disclosure Date: July 25, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.
Attacker Value
Unknown

CVE-2023-37905

Disclosure Date: July 21, 2023 (last updated February 25, 2025)
ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.