Show filters
219 Total Results
Displaying 141-150 of 219
Sort by:
Attacker Value
Unknown

CVE-2022-29947

Disclosure Date: April 29, 2022 (last updated February 23, 2025)
Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.
Attacker Value
Unknown

CVE-2022-1022

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
Attacker Value
Unknown

CVE-2021-24940

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-3813

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
Attacker Value
Unknown

CVE-2022-0527

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
Attacker Value
Unknown

CVE-2022-0526

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
Attacker Value
Unknown

CVE-2021-24928

Disclosure Date: February 07, 2022 (last updated February 23, 2025)
The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_order AJAX action, nor validation and escaping when inserting user data in SQL statement, leading to an SQL injection, and allowing any authenticated user, such as subscriber, to modify arbitrary post content (for example with an XSS payload), as well as exfiltrate any data by copying it to another post.
Attacker Value
Unknown

CVE-2021-24846

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber
Attacker Value
Unknown

CVE-2021-39308

Disclosure Date: December 14, 2021 (last updated February 23, 2025)
The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientref parameter found in the ~/processresponse.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.0.
0
Attacker Value
Unknown

CVE-2021-24938

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue