Show filters
219 Total Results
Displaying 121-130 of 219
Sort by:
Attacker Value
Unknown
CVE-2023-2109
Disclosure Date: April 17, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.
0
Attacker Value
Unknown
CVE-2023-0865
Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.
0
Attacker Value
Unknown
CVE-2015-10095
Disclosure Date: March 06, 2023 (last updated February 24, 2025)
A vulnerability classified as problematic has been found in woo-popup Plugin up to 1.2.2 on WordPress. This affects an unknown part of the file admin/class-woo-popup-admin.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.3.0 is able to address this issue. The patch is named 7c76ac78f3e16015991b612ff4fa616af4ce9292. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222327.
0
Attacker Value
Unknown
CVE-2023-0068
Disclosure Date: March 06, 2023 (last updated October 08, 2023)
The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2015-10048
Disclosure Date: January 15, 2023 (last updated February 24, 2025)
A vulnerability was found in bmattoso desafio_buzz_woody. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The identifier of the patch is cb8220cbae06082c969b1776fcb2fdafb3a1006b. It is recommended to apply a patch to fix this issue. The identifier VDB-218357 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-4329
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high privilege one like admin).
0
Attacker Value
Unknown
CVE-2021-30134
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
0
Attacker Value
Unknown
CVE-2022-3741
Disclosure Date: October 28, 2022 (last updated February 24, 2025)
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.
0
Attacker Value
Unknown
CVE-2022-3154
Disclosure Date: October 10, 2022 (last updated February 24, 2025)
The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin's license
0
Attacker Value
Unknown
CVE-2022-2575
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0