Show filters
171 Total Results
Displaying 11-20 of 171
Sort by:
Attacker Value
Unknown
CVE-2024-8052
Disclosure Date: September 17, 2024 (last updated September 28, 2024)
The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
0
Attacker Value
Unknown
CVE-2024-35630
Disclosure Date: June 03, 2024 (last updated February 26, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue affects WP TripAdvisor Review Slider: from n/a through 12.6.
0
Attacker Value
Unknown
CVE-2024-32685
Disclosure Date: May 17, 2024 (last updated February 26, 2025)
Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
0
Attacker Value
Unknown
CVE-2024-21746
Disclosure Date: May 17, 2024 (last updated February 26, 2025)
Authentication Bypass by Spoofing vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.3.2.
0
Attacker Value
Unknown
CVE-2024-2310
Disclosure Date: April 26, 2024 (last updated April 26, 2024)
The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2024-32684
Disclosure Date: April 22, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
0
Attacker Value
Unknown
CVE-2024-32683
Disclosure Date: April 19, 2024 (last updated February 26, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
0
Attacker Value
Unknown
CVE-2024-27999
Disclosure Date: March 28, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digamber Pradhan Preview E-mails for WooCommerce allows Reflected XSS.This issue affects Preview E-mails for WooCommerce: from n/a through 2.2.1.
0
Attacker Value
Unknown
CVE-2024-23139
Disclosure Date: March 18, 2024 (last updated February 26, 2025)
A maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-2553
Disclosure Date: March 17, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as problematic, was found in SourceCodester Product Review Rating System 1.0. Affected is an unknown function of the component Rate Product Handler. The manipulation of the argument Your Name/Comment leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257052.
0