Show filters
219 Total Results
Displaying 141-150 of 219
Sort by:
Attacker Value
Unknown
CVE-2022-29947
Disclosure Date: April 29, 2022 (last updated February 23, 2025)
Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.
0
Attacker Value
Unknown
CVE-2022-1022
Disclosure Date: April 21, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
0
Attacker Value
Unknown
CVE-2021-24940
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-3813
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
0
Attacker Value
Unknown
CVE-2022-0527
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
0
Attacker Value
Unknown
CVE-2022-0526
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
0
Attacker Value
Unknown
CVE-2021-24928
Disclosure Date: February 07, 2022 (last updated February 23, 2025)
The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_order AJAX action, nor validation and escaping when inserting user data in SQL statement, leading to an SQL injection, and allowing any authenticated user, such as subscriber, to modify arbitrary post content (for example with an XSS payload), as well as exfiltrate any data by copying it to another post.
0
Attacker Value
Unknown
CVE-2021-24846
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber
0
Attacker Value
Unknown
CVE-2021-39308
Disclosure Date: December 14, 2021 (last updated February 23, 2025)
The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientref parameter found in the ~/processresponse.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.0.
0
Attacker Value
Unknown
CVE-2021-24938
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue
0