Show filters
286 Total Results
Displaying 101-110 of 286
Sort by:
Attacker Value
Unknown
CVE-2022-2542
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-2541
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2021-4112
Disclosure Date: August 25, 2022 (last updated February 24, 2025)
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
0
Attacker Value
Unknown
CVE-2022-34786
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
0
Attacker Value
Unknown
CVE-2021-40642
Disclosure Date: June 29, 2022 (last updated February 24, 2025)
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.
0
Attacker Value
Unknown
CVE-2021-40658
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
0
Attacker Value
Unknown
CVE-2022-1395
Disclosure Date: May 30, 2022 (last updated February 23, 2025)
The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2022-22281
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system.
0
Attacker Value
Unknown
CVE-2022-27860
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.
0
Attacker Value
Unknown
CVE-2022-0737
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0