Show filters
193 Total Results
Displaying 101-110 of 193
Sort by:
Attacker Value
Unknown
CVE-2022-0439
Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.
0
Attacker Value
Unknown
CVE-2022-21179
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail Magazine Templates and/or transmitted history information may be deleted unintendedly.
0
Attacker Value
Unknown
CVE-2021-24874
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2021-24923
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-38302
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
0
Attacker Value
Unknown
CVE-2021-34658
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/simple-popup-newsletter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.7.
0
Attacker Value
Unknown
CVE-2021-34634
Disclosure Date: July 31, 2021 (last updated February 23, 2025)
The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.
0
Attacker Value
Unknown
CVE-2021-20743
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.
0
Attacker Value
Unknown
CVE-2020-35933
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encoded_options parameter.
0
Attacker Value
Unknown
CVE-2020-35932
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
0