Show filters
385 Total Results
Displaying 11-20 of 385
Sort by:
Attacker Value
Unknown
CVE-2025-0371
Disclosure Date: January 21, 2025 (last updated February 01, 2025)
The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2025-0369
Disclosure Date: January 18, 2025 (last updated January 18, 2025)
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-13296
Disclosure Date: January 09, 2025 (last updated January 10, 2025)
Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.
0
Attacker Value
Unknown
CVE-2023-48758
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.2.4.
0
Attacker Value
Unknown
CVE-2024-10858
Disclosure Date: December 25, 2024 (last updated January 05, 2025)
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.
0
Attacker Value
Unknown
CVE-2024-54436
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Jettochkin Jet Footer Code allows Stored XSS.This issue affects Jet Footer Code: from n/a through 1.4.
0
Attacker Value
Unknown
CVE-2024-11303
Disclosure Date: November 18, 2024 (last updated November 19, 2024)
The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601: through 1.2.
0
Attacker Value
Unknown
CVE-2024-10323
Disclosure Date: November 12, 2024 (last updated February 06, 2025)
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0
Attacker Value
Unknown
CVE-2024-9926
Disclosure Date: November 07, 2024 (last updated November 08, 2024)
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
0
Attacker Value
Unknown
CVE-2024-5749
Disclosure Date: October 15, 2024 (last updated October 16, 2024)
Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.
0