Show filters
219 Total Results
Displaying 131-140 of 219
Sort by:
Attacker Value
Unknown

CVE-2022-2901

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
Attacker Value
Unknown

CVE-2022-2555

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
Attacker Value
Unknown

CVE-2022-0542

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.
Attacker Value
Unknown

CVE-2022-1021

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.
Attacker Value
Unknown

CVE-2022-30998

Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.
Attacker Value
Unknown

CVE-2022-2099

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
Attacker Value
Unknown

CVE-2022-1933

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2022-1953

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first
Attacker Value
Unknown

CVE-2022-1470

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2022-0814

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections