Show filters
64 Total Results
Displaying 21-30 of 64
Sort by:
Attacker Value
Unknown
CVE-2023-49760
Disclosure Date: December 18, 2023 (last updated December 21, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.
0
Attacker Value
Unknown
CVE-2023-31275
Disclosure Date: November 27, 2023 (last updated December 01, 2023)
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-27458
Disclosure Date: November 22, 2023 (last updated December 01, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions.
0
Attacker Value
Unknown
CVE-2023-4776
Disclosure Date: October 16, 2023 (last updated October 20, 2023)
The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.
0
Attacker Value
Unknown
CVE-2023-39919
Disclosure Date: September 04, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in maennchen1.De wpShopGermany – Protected Shops plugin <= 2.0 versions.
0
Attacker Value
Unknown
CVE-2023-38512
Disclosure Date: July 27, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Wpstream WpStream – Live Streaming, Video on Demand, Pay Per View plugin <= 4.5.4 versions.
0
Attacker Value
Unknown
CVE-2023-37993
Disclosure Date: July 27, 2023 (last updated October 08, 2023)
Auth. Stored Cross-Site Scripting (XSS) vulnerability in maennchen1.De wpShopGermany IT-RECHT KANZLEI plugin <= 1.7 versions.
0
Attacker Value
Unknown
CVE-2023-32548
Disclosure Date: June 13, 2023 (last updated October 08, 2023)
OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed.
0
Attacker Value
Unknown
CVE-2020-36710
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
0
Attacker Value
Unknown
CVE-2022-2658
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0