Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2024-0796
Disclosure Date: February 05, 2024 (last updated February 14, 2024)
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6.1. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-51505
Disclosure Date: December 29, 2023 (last updated February 16, 2024)
Deserialization of Untrusted Data vulnerability in realmag777 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store.This issue affects Active Products Tables for WooCommerce. Professional products tables for WooCommerce store : from n/a through 1.0.6.
0
Attacker Value
Unknown
CVE-2023-2109
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.
0
Attacker Value
Unknown
CVE-2022-3741
Disclosure Date: October 28, 2022 (last updated December 22, 2024)
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.
0
Attacker Value
Unknown
CVE-2022-2901
Disclosure Date: September 06, 2022 (last updated October 08, 2023)
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
0
Attacker Value
Unknown
CVE-2022-0542
Disclosure Date: August 19, 2022 (last updated October 08, 2023)
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.
0
Attacker Value
Unknown
CVE-2022-1021
Disclosure Date: August 19, 2022 (last updated October 08, 2023)
Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.
0
Attacker Value
Unknown
CVE-2022-1916
Disclosure Date: June 27, 2022 (last updated February 16, 2024)
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-1022
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
0
Attacker Value
Unknown
CVE-2021-3813
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
0