Show filters
569 Total Results
Displaying 181-190 of 569
Sort by:
Attacker Value
Unknown
CVE-2020-23051
Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.
0
Attacker Value
Unknown
CVE-2021-24581
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.
0
Attacker Value
Unknown
CVE-2020-19704
Disclosure Date: August 26, 2021 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
0
Attacker Value
Unknown
CVE-2021-29377
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.
0
Attacker Value
Unknown
CVE-2021-24365
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.
0
Attacker Value
Unknown
CVE-2021-24366
Disclosure Date: June 21, 2021 (last updated November 08, 2023)
The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2021-29625
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to communicate with the database (it is used if the native extensions are not enabled). In browsers without CSP, Adminer versions 4.6.1 to 4.8.0 are affected. The vulnerability is patched in version 4.8.1. As workarounds, one can use a browser supporting strict CSP or enable the native PHP extensions (e.g. `mysqli`) or disable displaying PHP errors (`display_errors`).
0
Attacker Value
Unknown
CVE-2020-35296
Disclosure Date: March 03, 2021 (last updated February 22, 2025)
ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.
0
Attacker Value
Unknown
CVE-2020-26609
Disclosure Date: February 23, 2021 (last updated February 22, 2025)
fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain administrator credentials to log in to the background.
0
Attacker Value
Unknown
CVE-2021-21311
Disclosure Date: February 11, 2021 (last updated February 22, 2025)
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.
0