Show filters
75 Total Results
Displaying 11-20 of 75
Sort by:
Attacker Value
Unknown

CVE-2024-2306

Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.
0
Attacker Value
Unknown

CVE-2024-29771

Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Dracula Dark Mode - The Revolutionary Dark Mode Plugin For WordPress allows Stored XSS.This issue affects Dracula Dark Mode - The Revolutionary Dark Mode Plugin For WordPress: from n/a through 1.0.8.
0
Attacker Value
Unknown

CVE-2023-6528

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
Attacker Value
Unknown

CVE-2023-47784

Disclosure Date: December 20, 2023 (last updated December 28, 2023)
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
Attacker Value
Unknown

CVE-2023-47772

Disclosure Date: November 20, 2023 (last updated November 28, 2023)
Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14.
Attacker Value
Unknown

CVE-2023-28622

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions.
Attacker Value
Unknown

CVE-2023-2359

Disclosure Date: June 19, 2023 (last updated October 08, 2023)
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
Attacker Value
Unknown

CVE-2022-26149

Disclosure Date: February 26, 2022 (last updated October 07, 2023)
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
Attacker Value
Unknown

CVE-2020-25911

Disclosure Date: October 31, 2021 (last updated November 29, 2024)
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
Attacker Value
Unknown

CVE-2020-25179

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.