Show filters
447 Total Results
Displaying 171-180 of 447
Sort by:
Attacker Value
Unknown
CVE-2015-10073
Disclosure Date: February 06, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in tinymighty WikiSEO 1.2.1 on MediaWiki. This affects the function modifyHTML of the file WikiSEO.body.php of the component Meta Property Tag Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.2.2 is able to address this issue. The patch is named 089a5797be612b18a820f9f1e6593ad9a91b1dba. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220215.
0
Attacker Value
Unknown
CVE-2022-4548
Disclosure Date: January 23, 2023 (last updated February 24, 2025)
The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.
0
Attacker Value
Unknown
CVE-2022-4352
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2022-4351
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2022-23472
Disclosure Date: December 06, 2022 (last updated February 24, 2025)
Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python `random` library for random value selection. The python `random` library warns that it should not be used for security purposes due to its reliance on a non-cryptographically secure random number generator. As a result a motivated attacker may be able to guess generated passwords. This issue has been addressed in version 1.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2022-38140
Disclosure Date: November 28, 2022 (last updated February 24, 2025)
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
0
Attacker Value
Unknown
CVE-2022-42494
Disclosure Date: October 27, 2022 (last updated February 24, 2025)
Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.
0
Attacker Value
Unknown
CVE-2022-40695
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.
0
Attacker Value
Unknown
CVE-2022-36404
Disclosure Date: October 20, 2022 (last updated February 24, 2025)
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.
0
Attacker Value
Unknown
CVE-2022-44627
Disclosure Date: October 20, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers to create or delete sitemaps.
0