Show filters
241 Total Results
Displaying 131-140 of 241
Sort by:
Attacker Value
Unknown

CVE-2023-24409

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs plugin <= 1.1.15 versions.
Attacker Value
Unknown

CVE-2022-44276

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
Attacker Value
Unknown

CVE-2023-2482

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.
Attacker Value
Unknown

CVE-2023-0368

Disclosure Date: June 19, 2023 (last updated February 25, 2025)
The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2023-2184

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2021-31711

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to execute arbitrary code via the sort_by parameter in the dialog.php file.
Attacker Value
Unknown

CVE-2023-25982

Disclosure Date: May 04, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Eirudo Simple YouTube Responsive plugin <= 2.5 versions.
Attacker Value
Unknown

CVE-2018-25085

Disclosure Date: May 01, 2023 (last updated February 24, 2025)
A vulnerability classified as problematic was found in Responsive Menus 7.x-1.x-dev on Drupal. Affected by this vulnerability is the function responsive_menus_admin_form_submit of the file responsive_menus.module of the component Configuration Setting Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 7.x-1.7 is able to address this issue. The patch is named 3c554b31d32a367188f44d44857b061eac949fb8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-227755.
Attacker Value
Unknown

CVE-2023-22698

Disclosure Date: April 23, 2023 (last updated February 24, 2025)
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jason Bobich Theme Blvd Responsive Google Maps plugin <= 1.0.2 versions.
Attacker Value
Unknown

CVE-2023-2119

Disclosure Date: April 18, 2023 (last updated October 08, 2023)
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.