Show filters
102 Total Results
Displaying 11-20 of 102
Sort by:
Attacker Value
Unknown

CVE-2024-39713

Disclosure Date: August 05, 2024 (last updated August 31, 2024)
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Attacker Value
Unknown

CVE-2024-37258

Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Social Rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.3.
Attacker Value
Unknown

CVE-2024-37405

Disclosure Date: July 12, 2024 (last updated July 13, 2024)
Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.
0
Attacker Value
Unknown

CVE-2023-51407

Disclosure Date: March 16, 2024 (last updated April 01, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9.
0
Attacker Value
Unknown

CVE-2021-24432

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.
Attacker Value
Unknown

CVE-2023-23970

Disclosure Date: December 20, 2023 (last updated December 28, 2023)
Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.
Attacker Value
Unknown

CVE-2023-4951

Disclosure Date: September 14, 2023 (last updated October 08, 2023)
A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Configuration" screen of the GreenRADIUS web admin interface. This issue is found in GreenRADIUS v5.1.1.1 and prior. A fix was included in v5.1.2.2.
Attacker Value
Unknown

CVE-2023-3477

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
A vulnerability was found in RocketSoft Rocket LMS 1.7. It has been declared as problematic. This vulnerability affects unknown code of the file /contact/store of the component Contact Form. The manipulation of the argument name/subject/message leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-232756.
Attacker Value
Unknown

CVE-2023-23667

Disclosure Date: May 18, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions.
Attacker Value
Unknown

CVE-2023-28359

Disclosure Date: May 11, 2023 (last updated October 08, 2023)
A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability causes a delay in the server response, with the potential for limited impact.