Show filters
174 Total Results
Displaying 11-20 of 174
Sort by:
Attacker Value
Unknown
CVE-2024-1718
Disclosure Date: June 04, 2024 (last updated January 05, 2025)
The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the status of orders to paid bypassing payment.
0
Attacker Value
Unknown
CVE-2024-4419
Disclosure Date: May 29, 2024 (last updated January 05, 2025)
The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2023-51697
Disclosure Date: December 27, 2023 (last updated January 06, 2024)
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in `podcastUtils.js`. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-51665
Disclosure Date: December 27, 2023 (last updated January 06, 2024)
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth.js. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-47624
Disclosure Date: December 13, 2023 (last updated December 20, 2023)
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the `/hls` endpoint. This issue may lead to Information Disclosure. As of time of publication, no patches are available.
0
Attacker Value
Unknown
CVE-2023-47619
Disclosure Date: December 13, 2023 (last updated December 20, 2023)
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files and send a GET request to arbitrary URLs and read the response. This issue may lead to Information Disclosure. As of time of publication, no patches are available.
0
Attacker Value
Unknown
CVE-2023-6197
Disclosure Date: November 20, 2023 (last updated November 25, 2023)
The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missing or incorrect nonce validation on the audio_merchant_save_settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-6196
Disclosure Date: November 20, 2023 (last updated November 25, 2023)
The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missing or incorrect nonce validation on the function audio_merchant_add_audio_file function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-46396
Disclosure Date: October 25, 2023 (last updated November 03, 2023)
Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters.
0
Attacker Value
Unknown
CVE-2023-36361
Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.
0