Show filters
219 Total Results
Displaying 11-20 of 219
Sort by:
Attacker Value
Unknown
CVE-2023-50877
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in woobewoo Product Filter by WBW allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Filter by WBW: from n/a through 2.5.0.
0
Attacker Value
Unknown
CVE-2023-49848
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in wooproductimporter Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.
0
Attacker Value
Unknown
CVE-2023-48274
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Mondial Relay WooCommerce - WCMultiShipping WCMultiShipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCMultiShipping: from n/a through 2.3.5.
0
Attacker Value
Unknown
CVE-2023-30870
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in wooproductimporter Sharkdropship for AliExpress Dropship and Affiliate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharkdropship for AliExpress Dropship and Affiliate: from n/a through 2.2.3.
0
Attacker Value
Unknown
CVE-2024-51657
Disclosure Date: November 19, 2024 (last updated November 20, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2021-3742
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG file containing a malicious SSRF payload. When the SVG file is used as an avatar and opened in a new tab, it can trigger the SSRF, potentially leading to host redirection.
0
Attacker Value
Unknown
CVE-2021-3741
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malicious XSS payload in the profile settings. When the avatar is opened in a new page, the custom JavaScript code is executed, leading to potential security risks.
0
Attacker Value
Unknown
CVE-2021-3740
Disclosure Date: November 15, 2024 (last updated November 15, 2024)
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker has obtained a session token.
0
Attacker Value
Unknown
CVE-2024-50478
Disclosure Date: October 28, 2024 (last updated October 31, 2024)
Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.
0
Attacker Value
Unknown
CVE-2024-49691
Disclosure Date: October 24, 2024 (last updated October 25, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Woobewoo Product Filter by WBW allows SQL Injection.This issue affects Product Filter by WBW: from n/a through 2.7.0.
0