Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2019-11557

Disclosure Date: April 26, 2019 (last updated November 27, 2024)
The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
Attacker Value
Unknown

CVE-2018-16164

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-10504

Disclosure Date: April 27, 2018 (last updated November 26, 2024)
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
0
Attacker Value
Unknown

CVE-2018-10301

Disclosure Date: April 23, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post.
0
Attacker Value
Unknown

CVE-2018-10300

Disclosure Date: April 23, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio.
0
Attacker Value
Unknown

CVE-2018-5981

Disclosure Date: February 17, 2018 (last updated November 26, 2024)
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
0
Attacker Value
Unknown

CVE-2018-5991

Disclosure Date: February 17, 2018 (last updated November 26, 2024)
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.
0
Attacker Value
Unknown

CVE-2015-2798

Disclosure Date: July 25, 2017 (last updated November 26, 2024)
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2017-2224

Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-7719

Disclosure Date: April 12, 2017 (last updated November 26, 2024)
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.
0