Show filters
41 Total Results
Displaying 21-30 of 41
Sort by:
Attacker Value
Unknown

CVE-2022-44543

Disclosure Date: December 12, 2023 (last updated December 15, 2023)
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.
Attacker Value
Unknown

CVE-2022-45360

Disclosure Date: November 07, 2023 (last updated November 15, 2023)
Improper Neutralization of Formula Elements in a CSV File vulnerability in Scott Reilly Commenter Emails.This issue affects Commenter Emails: from n/a through 2.6.1.
Attacker Value
Unknown

CVE-2023-25014

Disclosure Date: February 02, 2023 (last updated October 08, 2023)
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.
Attacker Value
Unknown

CVE-2023-25013

Disclosure Date: February 02, 2023 (last updated October 08, 2023)
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.
Attacker Value
Unknown

CVE-2022-3343

Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the site by having another user send repeated follow actions to them.
Attacker Value
Unknown

CVE-2022-3688

Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could allow attackers to make logged in users perform such actions via CSRF attacks
Attacker Value
Unknown

CVE-2022-2198

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute forced.
Attacker Value
Unknown

CVE-2022-1323

Disclosure Date: August 08, 2022 (last updated February 24, 2025)
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.
Attacker Value
Unknown

CVE-2022-35628

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.
Attacker Value
Unknown

CVE-2022-1598

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.