Show filters
45 Total Results
Displaying 21-30 of 45
Sort by:
Attacker Value
Unknown
CVE-2022-1726
Disclosure Date: May 16, 2022 (last updated October 07, 2023)
Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.
0
Attacker Value
Unknown
CVE-2022-26624
Disclosure Date: April 08, 2022 (last updated October 07, 2023)
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.
0
Attacker Value
Unknown
CVE-2021-24933
Disclosure Date: February 28, 2022 (last updated October 07, 2023)
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-23472
Disclosure Date: November 03, 2021 (last updated November 28, 2024)
This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.
0
Attacker Value
Unknown
CVE-2021-40975
Disclosure Date: October 01, 2021 (last updated November 28, 2024)
Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.
0
Attacker Value
Unknown
CVE-2021-24635
Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL
0
Attacker Value
Unknown
CVE-2021-23398
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.
0
Attacker Value
Unknown
CVE-2020-25093
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
0
Attacker Value
Unknown
CVE-2020-25086
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
0
Attacker Value
Unknown
CVE-2020-25087
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
0