Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2021-27224

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-27362

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2019-9880

Disclosure Date: June 10, 2019 (last updated January 23, 2024)
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
0
Attacker Value
Unknown

CVE-2019-9881

Disclosure Date: June 10, 2019 (last updated January 23, 2024)
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
0
Attacker Value
Unknown

CVE-2019-9879

Disclosure Date: June 10, 2019 (last updated January 23, 2024)
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.
0
Attacker Value
Unknown

CVE-2018-5367

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php.
0
Attacker Value
Unknown

CVE-2018-5364

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to wp-admin/options.php.
0
Attacker Value
Unknown

CVE-2018-5363

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-admin/options.php.
0
Attacker Value
Unknown

CVE-2018-5366

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.
0
Attacker Value
Unknown

CVE-2018-5365

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to wp-admin/options.php.
0