Show filters
82 Total Results
Displaying 21-30 of 82
Sort by:
Attacker Value
Unknown

CVE-2022-45399

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.
Attacker Value
Unknown

CVE-2022-45398

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.
Attacker Value
Unknown

CVE-2022-33965

Disclosure Date: July 05, 2022 (last updated February 24, 2025)
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
Attacker Value
Unknown

CVE-2017-20099

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.
Attacker Value
Unknown

CVE-2022-27231

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.
Attacker Value
Unknown

CVE-2022-1005

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters
Attacker Value
Unknown

CVE-2022-0410

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection
Attacker Value
Unknown

CVE-2021-25042

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack of validation, sanitisation and escaping, users could set a malicious value and perform Cross-Site Scripting attacks against logged in admin
Attacker Value
Unknown

CVE-2022-25307

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.
Attacker Value
Unknown

CVE-2022-25306

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.