Show filters
406 Total Results
Displaying 121-130 of 406
Sort by:
Attacker Value
Unknown
CVE-2022-4485
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Page-list WordPress plugin before 5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-43462
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
Auth. SQL Injection (SQLi) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
0
Attacker Value
Unknown
CVE-2022-42462
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
0
Attacker Value
Unknown
CVE-2015-10045
Disclosure Date: January 15, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in tutrantta project_todolist. Affected is the function getAffectedRows/where/insert/update in the library library/Database.php. The manipulation leads to sql injection. The name of the patch is 194a0411bbe11aa4813f13c66b9e8ea403539141. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218352.
0
Attacker Value
Unknown
CVE-2022-4360
Disclosure Date: January 02, 2023 (last updated February 24, 2025)
The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2022-4359
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2022-4358
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2022-4329
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high privilege one like admin).
0
Attacker Value
Unknown
CVE-2022-4604
Disclosure Date: December 18, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function register_endpoints of the file english-wp-admin.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1.5.2 is able to address this issue. The name of the patch is ad4ba171c974c65c3456e7c6228f59f40783b33d. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216199.
0
Attacker Value
Unknown
CVE-2022-45969
Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Alist v3.4.0 is vulnerable to Directory Traversal,
0