Show filters
102 Total Results
Displaying 11-20 of 102
Sort by:
Attacker Value
Unknown
CVE-2024-39713
Disclosure Date: August 05, 2024 (last updated August 31, 2024)
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
0
Attacker Value
Unknown
CVE-2024-37258
Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Social Rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.3.
0
Attacker Value
Unknown
CVE-2024-37405
Disclosure Date: July 12, 2024 (last updated July 13, 2024)
Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.
0
Attacker Value
Unknown
CVE-2023-51407
Disclosure Date: March 16, 2024 (last updated April 01, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9.
0
Attacker Value
Unknown
CVE-2021-24432
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2023-23970
Disclosure Date: December 20, 2023 (last updated December 28, 2023)
Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.
0
Attacker Value
Unknown
CVE-2023-4951
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Configuration" screen of the GreenRADIUS web admin interface. This issue is found in GreenRADIUS v5.1.1.1 and prior. A fix was included in v5.1.2.2.
0
Attacker Value
Unknown
CVE-2023-3477
Disclosure Date: June 30, 2023 (last updated October 08, 2023)
A vulnerability was found in RocketSoft Rocket LMS 1.7. It has been declared as problematic. This vulnerability affects unknown code of the file /contact/store of the component Contact Form. The manipulation of the argument name/subject/message leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-232756.
0
Attacker Value
Unknown
CVE-2023-23667
Disclosure Date: May 18, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions.
0
Attacker Value
Unknown
CVE-2023-28359
Disclosure Date: May 11, 2023 (last updated October 08, 2023)
A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability causes a delay in the server response, with the potential for limited impact.
0