Show filters
242 Total Results
Displaying 151-160 of 242
Sort by:
Attacker Value
Unknown

CVE-2022-3987

Disclosure Date: December 19, 2022 (last updated February 24, 2025)
The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-36375

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.
Attacker Value
Unknown

CVE-2017-20145

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended to upgrade the affected component.
Attacker Value
Unknown

CVE-2022-29659

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.
Attacker Value
Unknown

CVE-2022-1298

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-36893

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
Attacker Value
Unknown

CVE-2022-25602

Disclosure Date: March 16, 2022 (last updated February 23, 2025)
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).
Attacker Value
Unknown

CVE-2021-24995

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2021-24971

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting attacks against all visitor and users on the frontend
Attacker Value
Unknown

CVE-2021-24947

Disclosure Date: February 07, 2022 (last updated February 23, 2025)
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server