Show filters
88 Total Results
Displaying 21-30 of 88
Sort by:
Attacker Value
Unknown
CVE-2024-37557
Disclosure Date: July 21, 2024 (last updated September 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Soham Web Solution WP Cookie Law Info allows Stored XSS.This issue affects WP Cookie Law Info: from n/a through 1.1.
0
Attacker Value
Unknown
CVE-2024-4869
Disclosure Date: June 26, 2024 (last updated January 05, 2025)
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-35692
Disclosure Date: June 11, 2024 (last updated July 24, 2024)
Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.
0
Attacker Value
Unknown
CVE-2024-32784
Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in CookieHub.This issue affects CookieHub: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-5607
Disclosure Date: June 07, 2024 (last updated October 30, 2024)
The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions named ajaxUpdateSettings() in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings, update page content, send arbitrary emails and inject malicious web scripts.
0
Attacker Value
Unknown
CVE-2024-3599
Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to delete arbitrary posts.
0
Attacker Value
Unknown
CVE-2023-45289
Disclosure Date: March 05, 2024 (last updated March 06, 2024)
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
0
Attacker Value
Unknown
CVE-2023-49191
Disclosure Date: December 15, 2023 (last updated December 22, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic GDPR Cookie Consent by Supsystic allows Stored XSS.This issue affects GDPR Cookie Consent by Supsystic: from n/a through 2.1.2.
0
Attacker Value
Unknown
CVE-2023-49836
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brontobytes Cookie Bar allows Stored XSS.This issue affects Cookie Bar: from n/a through 2.0.
0
Attacker Value
Unknown
CVE-2023-40662
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jonk @ Follow me Darling Cookies and Content Security Policy.This issue affects Cookies and Content Security Policy: from n/a through 2.15.
0