Show filters
13,174 Total Results
Displaying 1,011-1,020 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-22625

Disclosure Date: January 16, 2024 (last updated January 20, 2024)
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_category.php?id=.
Attacker Value
Unknown

CVE-2023-7154

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2023-6732

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2023-6046

Disclosure Date: January 16, 2024 (last updated January 20, 2024)
The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2023-6005

Disclosure Date: January 16, 2024 (last updated January 20, 2024)
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2023-4797

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
Attacker Value
Unknown

CVE-2023-3647

Disclosure Date: January 16, 2024 (last updated January 23, 2024)
The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2023-2655

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
Attacker Value
Unknown

CVE-2023-2252

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.
Attacker Value
Unknown

CVE-2023-0389

Disclosure Date: January 16, 2024 (last updated January 23, 2024)
The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)