Show filters
36 Total Results
Displaying 11-20 of 36
Sort by:
Attacker Value
Unknown

CVE-2021-40909

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
Attacker Value
Unknown

CVE-2021-43853

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious user. The affected core relates to JavaScript object creation when parsing json input. Releases before version 21.12.22.1 are affected. A workaround exists that replaces one of the core JavaScript files embedded in the library. See the GHSA-5q7q-qqw2-hjq7 for workaround details.
Attacker Value
Unknown

CVE-2016-10929

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.
0
Attacker Value
Unknown

CVE-2018-15876

Disclosure Date: August 26, 2018 (last updated November 27, 2024)
An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and password-recovery form require solving a CAPTCHA to perform actions. However, this is required only once per user session, and therefore one could send as many requests as one wished by automation.
0
Attacker Value
Unknown

CVE-2014-2674

Disclosure Date: March 19, 2018 (last updated November 26, 2024)
Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the loop parameter in an ajax_navigation action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2014-4972

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms.
0
Attacker Value
Unknown

CVE-2016-1000127

Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin ajax-random-post v2.00
0
Attacker Value
Unknown

CVE-2015-5650

Disclosure Date: October 06, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in AjaXplorer 2.0 allows remote attackers to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-3392

Disclosure Date: April 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ajax Timeline module before 7.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.
0
Attacker Value
Unknown

CVE-2012-5853

Disclosure Date: January 08, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a "the_search_text" action to wp-admin/admin-ajax.php.
0