Show filters
581 Total Results
Displaying 101-110 of 581
Sort by:
Attacker Value
Unknown

CVE-2023-47308

Disclosure Date: November 15, 2023 (last updated February 25, 2025)
In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Attacker Value
Unknown

CVE-2023-47680

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Qode Interactive Qi Addons For Elementor plugin <= 1.6.3 versions.
Attacker Value
Unknown

CVE-2023-31088

Disclosure Date: November 09, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Faraz Quazi Floating Action Button plugin <= 1.2.1 versions.
Attacker Value
Unknown

CVE-2023-32587

Disclosure Date: November 09, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in WP Reactions, LLC WP Reactions Lite plugin <= 1.3.8 versions.
Attacker Value
Unknown

CVE-2023-5082

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.
Attacker Value
Unknown

CVE-2023-47184

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions.
Attacker Value
Unknown

CVE-2023-45024

Disclosure Date: November 03, 2023 (last updated February 25, 2025)
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
Attacker Value
Unknown

CVE-2023-41260

Disclosure Date: November 03, 2023 (last updated February 25, 2025)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
Attacker Value
Unknown

CVE-2023-41259

Disclosure Date: November 03, 2023 (last updated February 25, 2025)
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
Attacker Value
Unknown

CVE-2023-46490

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.