Show filters
219 Total Results
Displaying 131-140 of 219
Sort by:
Attacker Value
Unknown
CVE-2022-2901
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
0
Attacker Value
Unknown
CVE-2022-2555
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
0
Attacker Value
Unknown
CVE-2022-0542
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.
0
Attacker Value
Unknown
CVE-2022-1021
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.
0
Attacker Value
Unknown
CVE-2022-30998
Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-2099
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
0
Attacker Value
Unknown
CVE-2022-1933
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-1953
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first
0
Attacker Value
Unknown
CVE-2022-1470
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-0814
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections
0