Show filters
51 Total Results
Displaying 11-20 of 51
Sort by:
Attacker Value
Unknown
CVE-2023-37973
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions.
0
Attacker Value
Unknown
CVE-2022-46850
Disclosure Date: June 19, 2023 (last updated October 08, 2023)
Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions.
0
Attacker Value
Unknown
CVE-2020-36660
Disclosure Date: February 06, 2023 (last updated October 20, 2023)
A vulnerability was found in paxswill EVE Ship Replacement Program 0.12.11. It has been rated as problematic. This issue affects some unknown processing of the file src/evesrp/views/api.py of the component User Information Handler. The manipulation leads to information disclosure. The attack may be initiated remotely. Upgrading to version 0.12.12 is able to address this issue. The patch is named 9e03f68e46e85ca9c9694a6971859b3ee66f0240. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220211.
0
Attacker Value
Unknown
CVE-2022-4675
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Mongoose Page Plugin WordPress plugin before 1.9.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
0
Attacker Value
Unknown
CVE-2022-3850
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-2311
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2022-30004
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..
0
Attacker Value
Unknown
CVE-2022-30003
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.
0
Attacker Value
Unknown
CVE-2022-2657
Disclosure Date: September 05, 2022 (last updated October 08, 2023)
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF
0
Attacker Value
Unknown
CVE-2022-1772
Disclosure Date: June 13, 2022 (last updated October 07, 2023)
The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.
0