Show filters
141 Total Results
Displaying 11-20 of 141
Sort by:
Attacker Value
Unknown

CVE-2024-2222

Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_callback_delete_attachment function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber access or higher, to delete arbitrary media uploads.
0
Attacker Value
Unknown

CVE-2023-51474

Disclosure Date: March 16, 2024 (last updated April 01, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Pixelemu TerraClassifieds.This issue affects TerraClassifieds: from n/a through 2.0.3.
0
Attacker Value
Unknown

CVE-2023-51473

Disclosure Date: December 29, 2023 (last updated January 06, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.This issue affects TerraClassifieds – Simple Classifieds Plugin: from n/a through 2.0.3.
Attacker Value
Unknown

CVE-2023-46207

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.
Attacker Value
Unknown

CVE-2023-46208

Disclosure Date: October 27, 2023 (last updated November 01, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.
Attacker Value
Unknown

CVE-2023-41801

Disclosure Date: October 06, 2023 (last updated September 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.
Attacker Value
Unknown

CVE-2022-38716

Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions.
Attacker Value
Unknown

CVE-2022-3989

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
Attacker Value
Unknown

CVE-2022-3254

Disclosure Date: October 31, 2022 (last updated September 26, 2024)
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection
Attacker Value
Unknown

CVE-2017-20136

Disclosure Date: July 16, 2022 (last updated October 07, 2023)
A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function of the file /subpage.php. The manipulation of the argument scat with the input =51' AND 4941=4941 AND 'hoCP'='hoCP leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.