Show filters
88 Total Results
Displaying 21-30 of 88
Sort by:
Attacker Value
Unknown

CVE-2024-37557

Disclosure Date: July 21, 2024 (last updated September 06, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Soham Web Solution WP Cookie Law Info allows Stored XSS.This issue affects WP Cookie Law Info: from n/a through 1.1.
Attacker Value
Unknown

CVE-2024-4869

Disclosure Date: June 26, 2024 (last updated January 05, 2025)
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2024-35692

Disclosure Date: June 11, 2024 (last updated July 24, 2024)
Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.
Attacker Value
Unknown

CVE-2024-32784

Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in CookieHub.This issue affects CookieHub: from n/a through 1.1.0.
0
Attacker Value
Unknown

CVE-2024-5607

Disclosure Date: June 07, 2024 (last updated October 30, 2024)
The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions named ajaxUpdateSettings() in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings, update page content, send arbitrary emails and inject malicious web scripts.
Attacker Value
Unknown

CVE-2024-3599

Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to delete arbitrary posts.
0
Attacker Value
Unknown

CVE-2023-45289

Disclosure Date: March 05, 2024 (last updated March 06, 2024)
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
0
Attacker Value
Unknown

CVE-2023-49191

Disclosure Date: December 15, 2023 (last updated December 22, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic GDPR Cookie Consent by Supsystic allows Stored XSS.This issue affects GDPR Cookie Consent by Supsystic: from n/a through 2.1.2.
Attacker Value
Unknown

CVE-2023-49836

Disclosure Date: December 14, 2023 (last updated December 19, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brontobytes Cookie Bar allows Stored XSS.This issue affects Cookie Bar: from n/a through 2.0.
Attacker Value
Unknown

CVE-2023-40662

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jonk @ Follow me Darling Cookies and Content Security Policy.This issue affects Cookies and Content Security Policy: from n/a through 2.15.