Show filters
1,056 Total Results
Displaying 11-20 of 1,056
Sort by:
Attacker Value
Unknown

CVE-2025-22539

Disclosure Date: January 09, 2025 (last updated January 10, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBase Tables allows Reflected XSS.This issue affects Custom DataBase Tables: from n/a through 2.1.34.
0
Attacker Value
Unknown

CVE-2024-12330

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all information stored in the database.
Attacker Value
Unknown

CVE-2025-22351

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenguinArts Contact Form 7 Database – CFDB7 allows SQL Injection.This issue affects Contact Form 7 Database – CFDB7: from n/a through 1.0.0.
0
Attacker Value
Unknown

CVE-2024-12850

Disclosure Date: December 24, 2024 (last updated January 05, 2025)
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Attacker Value
Unknown

CVE-2023-49167

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Code4Life Database for CF7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database for CF7: from n/a through 1.2.4.
0
Attacker Value
Unknown

CVE-2024-10311

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin settings and log in as any existing user on the site, such as an administrator.
Attacker Value
Unknown

CVE-2024-49042

Disclosure Date: November 12, 2024 (last updated January 13, 2025)
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2024-43613

Disclosure Date: November 12, 2024 (last updated January 13, 2025)
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2024-43300

Disclosure Date: October 18, 2024 (last updated October 23, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bert Kößler Movie Database allows Stored XSS.This issue affects Movie Database: from n/a through 1.0.11.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.