Show filters
267 Total Results
Displaying 161-170 of 267
Sort by:
Attacker Value
Unknown

CVE-2020-23044

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2021-36871

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.
Attacker Value
Unknown

CVE-2021-36870

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.
Attacker Value
Unknown

CVE-2020-18114

Disclosure Date: August 27, 2021 (last updated February 23, 2025)
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
Attacker Value
Unknown

CVE-2020-18917

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Attacker Value
Unknown

CVE-2021-23420

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.
Attacker Value
Unknown

CVE-2021-24383

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2020-22198

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
Attacker Value
Unknown

CVE-2020-16632

Disclosure Date: May 15, 2021 (last updated February 22, 2025)
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
Attacker Value
Unknown

CVE-2021-32073

Disclosure Date: May 15, 2021 (last updated February 22, 2025)
DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.