Show filters
100 Total Results
Displaying 1-10 of 100
Sort by:
Attacker Value
Unknown

CVE-2024-55864

Disclosure Date: December 17, 2024 (last updated December 18, 2024)
Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page.
0
Attacker Value
Unknown

CVE-2024-53278

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the admin screen.
0
Attacker Value
Unknown

CVE-2024-9506

Disclosure Date: October 15, 2024 (last updated October 16, 2024)
Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.
0
Attacker Value
Unknown

CVE-2024-6783

Disclosure Date: July 23, 2024 (last updated July 24, 2024)
A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code.
0
Attacker Value
Unknown

CVE-2024-3030

Disclosure Date: April 04, 2024 (last updated April 10, 2024)
The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown

CVE-2023-5718

Disclosure Date: October 23, 2023 (last updated November 01, 2023)
The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By creating a malicious web page with an iFrame targeting a sensitive resource (i.e. a locally accessible file or sensitive website), and registering a listener on the web page, the extension sent messages back to the listener, containing the base64 encoded screenshot data of the sensitive resource.
Attacker Value
Unknown

CVE-2023-45011

Disclosure Date: October 12, 2023 (last updated October 18, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Igor Buyanov WP Power Stats plugin <= 2.2.3 versions.
Attacker Value
Unknown

CVE-2023-4766

Disclosure Date: September 14, 2023 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Movus allows SQL Injection.This issue affects Movus: before 20230913.
Attacker Value
Unknown

CVE-2021-46312

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An issue was discovered IW44EncodeCodec.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.
Attacker Value
Unknown

CVE-2021-46310

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An issue was discovered IW44Image.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.