Show filters
180 Total Results
Displaying 101-110 of 180
Sort by:
Attacker Value
Unknown
CVE-2021-24851
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.
0
Attacker Value
Unknown
CVE-2021-24850
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by storing the payload/s in another post's custom fields.
0
Attacker Value
Unknown
CVE-2021-29907
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force ID: 207633.
0
Attacker Value
Unknown
CVE-2021-38343
Disclosure Date: August 25, 2021 (last updated February 23, 2025)
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.
0
Attacker Value
Unknown
CVE-2021-38342
Disclosure Date: August 25, 2021 (last updated February 23, 2025)
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.
0
Attacker Value
Unknown
CVE-2020-4535
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182906.
0
Attacker Value
Unknown
CVE-2020-4536
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182907.
0
Attacker Value
Unknown
CVE-2020-6324
Disclosure Date: September 09, 2020 (last updated February 22, 2025)
SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacker to send polluted URL to the victim, when the victim clicks on this URL, the attacker can read, modify the information available in the victim�s browser leading to Reflected Cross Site Scripting.
0
Attacker Value
Unknown
CVE-2020-6246
Disclosure Date: June 10, 2020 (last updated February 21, 2025)
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2020-6213
Disclosure Date: April 24, 2020 (last updated February 21, 2025)
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled inputs.
0