Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2019-14470
Disclosure Date: September 04, 2019 (last updated November 27, 2024)
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
0
Attacker Value
Unknown
CVE-2018-13849
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.
0
Attacker Value
Unknown
CVE-2018-10301
Disclosure Date: April 23, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post.
0
Attacker Value
Unknown
CVE-2018-10300
Disclosure Date: April 23, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio.
0
Attacker Value
Unknown
CVE-2017-17869
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.
0
Attacker Value
Unknown
CVE-2017-16758
Disclosure Date: November 09, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "access_token" parameter.
0
Attacker Value
Unknown
CVE-2014-6834
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The Instaroid - Instagram Viewer (aka net.muik.instaroid) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6690
Disclosure Date: September 23, 2014 (last updated October 05, 2023)
The InstaMessage - Instagram Chat (aka com.futurebits.instamessage.free) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6007
Disclosure Date: September 22, 2014 (last updated October 05, 2023)
The LikeHero Get Instagram Likes (aka com.fraoula.likehero) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-5675
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0