Show filters
219 Total Results
Displaying 151-160 of 219
Sort by:
Attacker Value
Unknown

CVE-2021-43676

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
Attacker Value
Unknown

CVE-2021-42367

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/class-menu-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1. Due to missing authorization checks on the tawcvs_save_settings function, low-level authenticated users such as subscribers can exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-42363

Disclosure Date: November 18, 2021 (last updated February 23, 2025)
The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.
0
Attacker Value
Unknown

CVE-2021-24607

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
Attacker Value
Unknown

CVE-2021-32790

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-json/wc/v3/webhooks`, `/wp-json/wc/v2/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a patch for this vulnerability. There are no known workarounds other than upgrading.
Attacker Value
Unknown

CVE-2021-3649

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
chatwoot is vulnerable to Inefficient Regular Expression Complexity
Attacker Value
Unknown

CVE-2021-24323

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled
Attacker Value
Unknown

CVE-2021-24212

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.
Attacker Value
Unknown

CVE-2021-26710

Disclosure Date: February 05, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.
Attacker Value
Unknown

CVE-2021-26711

Disclosure Date: February 05, 2021 (last updated February 22, 2025)
A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parameter.