Show filters
64 Total Results
Displaying 11-20 of 64
Sort by:
Attacker Value
Unknown
CVE-2023-23814
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13.
0
Attacker Value
Unknown
CVE-2024-9940
Disclosure Date: October 17, 2024 (last updated January 06, 2025)
The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views form submissions in their email.
0
Attacker Value
Unknown
CVE-2024-47297
Disclosure Date: October 06, 2024 (last updated October 07, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople CP Polls allows Reflected XSS.This issue affects CP Polls: from n/a through 1.0.74.
0
Attacker Value
Unknown
CVE-2024-35735
Disclosure Date: June 10, 2024 (last updated June 13, 2024)
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.11.
0
Attacker Value
Unknown
CVE-2024-33543
Disclosure Date: June 09, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.
0
Attacker Value
Unknown
CVE-2024-35734
Disclosure Date: June 08, 2024 (last updated July 19, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form allows Stored XSS.This issue affects WP Time Slots Booking Form: from n/a through 1.2.10.
0
Attacker Value
Unknown
CVE-2024-36082
Disclosure Date: June 07, 2024 (last updated July 18, 2024)
SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary SQL commands. Information stored in the database may be obtained or altered by the attacker.
0
Attacker Value
Unknown
CVE-2023-48318
Disclosure Date: June 04, 2024 (last updated June 04, 2024)
Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41.
0
Attacker Value
Unknown
CVE-2023-28494
Disclosure Date: June 04, 2024 (last updated June 04, 2024)
Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.
0
Attacker Value
Unknown
CVE-2023-28492
Disclosure Date: June 03, 2024 (last updated June 04, 2024)
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.
0