Show filters
241 Total Results
Displaying 131-140 of 241
Sort by:
Attacker Value
Unknown
CVE-2023-24409
Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs plugin <= 1.1.15 versions.
0
Attacker Value
Unknown
CVE-2022-44276
Disclosure Date: June 28, 2023 (last updated February 25, 2025)
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
0
Attacker Value
Unknown
CVE-2023-2482
Disclosure Date: June 27, 2023 (last updated February 25, 2025)
The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.
0
Attacker Value
Unknown
CVE-2023-0368
Disclosure Date: June 19, 2023 (last updated February 25, 2025)
The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2023-2184
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2021-31711
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to execute arbitrary code via the sort_by parameter in the dialog.php file.
0
Attacker Value
Unknown
CVE-2023-25982
Disclosure Date: May 04, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Eirudo Simple YouTube Responsive plugin <= 2.5 versions.
0
Attacker Value
Unknown
CVE-2018-25085
Disclosure Date: May 01, 2023 (last updated February 24, 2025)
A vulnerability classified as problematic was found in Responsive Menus 7.x-1.x-dev on Drupal. Affected by this vulnerability is the function responsive_menus_admin_form_submit of the file responsive_menus.module of the component Configuration Setting Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 7.x-1.7 is able to address this issue. The patch is named 3c554b31d32a367188f44d44857b061eac949fb8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-227755.
0
Attacker Value
Unknown
CVE-2023-22698
Disclosure Date: April 23, 2023 (last updated February 24, 2025)
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jason Bobich Theme Blvd Responsive Google Maps plugin <= 1.0.2 versions.
0
Attacker Value
Unknown
CVE-2023-2119
Disclosure Date: April 18, 2023 (last updated October 08, 2023)
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0