Show filters
727 Total Results
Displaying 151-160 of 727
Sort by:
Attacker Value
Unknown

CVE-2022-3768

Disclosure Date: November 28, 2022 (last updated February 24, 2025)
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
Attacker Value
Unknown

CVE-2022-3477

Disclosure Date: November 14, 2022 (last updated February 24, 2025)
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
Attacker Value
Unknown

CVE-2022-3244

Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce
Attacker Value
Unknown

CVE-2022-3243

Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
Attacker Value
Unknown

CVE-2022-1270

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
Attacker Value
Unknown

CVE-2022-3135

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2022-38577

Disclosure Date: September 19, 2022 (last updated February 24, 2025)
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
Attacker Value
Unknown

CVE-2022-1194

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
Attacker Value
Unknown

CVE-2022-29649

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2018-25047

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.