Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown
CVE-2022-29353
Disclosure Date: May 16, 2022 (last updated February 23, 2025)
An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename.
0
Attacker Value
Unknown
CVE-2019-25060
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.
0
Attacker Value
Unknown
CVE-2022-21708
Disclosure Date: January 21, 2022 (last updated February 23, 2025)
graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability that is possible due to a bug in the library that would allow an attacker with specifically designed queries to cause stack overflow panics. Any user with access to the GraphQL handler can send these queries and cause stack overflows. This in turn could potentially compromise the ability of the server to serve data to its users. The issue has been patched in version `v1.3.0`. The only known workaround for this issue is to disable the `graphql.MaxDepth` option from your schema which is not recommended.
0
Attacker Value
Unknown
CVE-2021-23326
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.
0
Attacker Value
Unknown
CVE-2020-4038
Disclosure Date: June 08, 2020 (last updated February 21, 2025)
GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the associated dependent middleware packages are also affected including but not limited to graphql-playground-middleware-express before version 1.7.16, graphql-playground-middleware-koa before version 1.6.15, graphql-playground-middleware-lambda before version 1.7.17, and graphql-playground-middleware-hapi before 1.6.13.
0
Attacker Value
Unknown
CVE-2019-1020015
Disclosure Date: July 29, 2019 (last updated November 27, 2024)
graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.
0
Attacker Value
Unknown
CVE-2019-9880
Disclosure Date: June 10, 2019 (last updated January 23, 2024)
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
0
Attacker Value
Unknown
CVE-2019-9879
Disclosure Date: June 10, 2019 (last updated January 23, 2024)
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.
0
Attacker Value
Unknown
CVE-2019-9881
Disclosure Date: June 10, 2019 (last updated January 23, 2024)
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
0