Show filters
332 Total Results
Displaying 141-150 of 332
Sort by:
Attacker Value
Unknown

CVE-2022-2740

Disclosure Date: August 11, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-2736

Disclosure Date: August 11, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-205881 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-2725

Disclosure Date: August 09, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-35493

Disclosure Date: August 08, 2022 (last updated February 24, 2025)
A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.
Attacker Value
Unknown

CVE-2022-2269

Disclosure Date: August 08, 2022 (last updated February 24, 2025)
The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL injection
Attacker Value
Unknown

CVE-2022-2702

Disclosure Date: August 08, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-205826 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-2694

Disclosure Date: August 06, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205817 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-29455

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
Attacker Value
Unknown

CVE-2022-30015

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.
Attacker Value
Unknown

CVE-2022-30014

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.