Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown

CVE-2024-0836

Disclosure Date: January 31, 2024 (last updated February 06, 2024)
The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtrs_review_edit() function in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary reviews.
Attacker Value
Unknown

CVE-2023-36682

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7.
Attacker Value
Unknown

CVE-2021-4403

Disclosure Date: July 01, 2023 (last updated November 09, 2023)
The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-25058

Disclosure Date: May 26, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions.
Attacker Value
Unknown

CVE-2022-33154

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS.
Attacker Value
Unknown

CVE-2021-25060

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2021-3918

Disclosure Date: November 13, 2021 (last updated February 23, 2025)
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Attacker Value
Unknown

CVE-2021-21267

Disclosure Date: March 19, 2021 (last updated February 22, 2025)
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `a@0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.`) will freeze the program or web browser page executing the code. This affects any current schema-inspector users using any version to validate email addresses. Users who do not do email validation, and instead do other types of validation (like string min or max length, etc), are not affected. Users should upgrade to version 2.0.0, which uses a regex expression that isn't vulnerable to ReDoS.
Attacker Value
Unknown

CVE-2020-7742

Disclosure Date: October 07, 2020 (last updated November 28, 2024)
This affects the package simpl-schema before 1.10.2.
0
Attacker Value
Unknown

CVE-2018-20977

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
0