Show filters
156 Total Results
Displaying 141-150 of 156
Sort by:
Attacker Value
Unknown

CVE-2021-24884

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These actions include stealing the users account by changing their password or allowing attackers to submit their own code through an authenticated user resulting in Remote Code Execution. If an authenticated user who is able to edit Wordpress PHP Code in any kind, clicks the malicious link, PHP code can be edi…
Attacker Value
Unknown

CVE-2021-24514

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-24608

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-24513

Disclosure Date: September 06, 2021 (last updated February 23, 2025)
The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-24224

Disclosure Date: April 12, 2021 (last updated February 22, 2025)
The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.
Attacker Value
Unknown

CVE-2021-3344

Disclosure Date: March 16, 2021 (last updated February 22, 2025)
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use the credentials to overwrite arbitrary container images in internal registries and/or escalate their privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This affects github.com/openshift/builder v0.0.0-20210125201112-7901cb396121 and before.
Attacker Value
Unknown

CVE-2020-13423

Disclosure Date: June 29, 2020 (last updated February 21, 2025)
Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.
Attacker Value
Unknown

CVE-2019-15780

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
Attacker Value
Unknown

CVE-2019-12139

Disclosure Date: May 16, 2019 (last updated November 27, 2024)
An XSS issue was discovered in the Admin UI in eZ Platform 2.x. This affects ezplatform-admin-ui 1.3.x before 1.3.5 and 1.4.x before 1.4.4, and ezplatform-page-builder 1.1.x before 1.1.5 and 1.2.x before 1.2.4.
0
Attacker Value
Unknown

CVE-2019-11557

Disclosure Date: April 26, 2019 (last updated November 27, 2024)
The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.