Show filters
267 Total Results
Displaying 161-170 of 267
Sort by:
Attacker Value
Unknown
CVE-2020-23044
Disclosure Date: October 22, 2021 (last updated February 23, 2025)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
0
Attacker Value
Unknown
CVE-2021-36871
Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.
0
Attacker Value
Unknown
CVE-2021-36870
Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.
0
Attacker Value
Unknown
CVE-2020-18114
Disclosure Date: August 27, 2021 (last updated February 23, 2025)
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
0
Attacker Value
Unknown
CVE-2020-18917
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
0
Attacker Value
Unknown
CVE-2021-23420
Disclosure Date: August 11, 2021 (last updated February 23, 2025)
This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.
0
Attacker Value
Unknown
CVE-2021-24383
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2020-22198
Disclosure Date: June 16, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
0
Attacker Value
Unknown
CVE-2020-16632
Disclosure Date: May 15, 2021 (last updated February 22, 2025)
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
0
Attacker Value
Unknown
CVE-2021-32073
Disclosure Date: May 15, 2021 (last updated February 22, 2025)
DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.
0