Show filters
97 Total Results
Displaying 21-30 of 97
Sort by:
Attacker Value
Unknown
CVE-2024-37954
Disclosure Date: July 20, 2024 (last updated August 31, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in marcelotorres Simple Responsive Slider allows Reflected XSS.This issue affects Simple Responsive Slider: from n/a through 0.2.2.5.
0
Attacker Value
Unknown
CVE-2024-32695
Disclosure Date: April 22, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Gasi Language Switcher for Transposh allows Reflected XSS.This issue affects Language Switcher for Transposh: from n/a through 1.5.9.
0
Attacker Value
Unknown
CVE-2024-21752
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affects Ajax Search Lite: from n/a through 4.11.4.
0
Attacker Value
Unknown
CVE-2024-1496
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and including, 4.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-4539
Disclosure Date: February 15, 2024 (last updated February 26, 2025)
Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations.
This issue affects ERP XL: from 2020.2.2 through 2023.2.
0
Attacker Value
Unknown
CVE-2023-4538
Disclosure Date: February 15, 2024 (last updated February 26, 2025)
The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords.
This issue affects ERP XL: from 2020.2.2 through 2023.2.
0
Attacker Value
Unknown
CVE-2023-4537
Disclosure Date: February 15, 2024 (last updated February 26, 2025)
Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.
This issue affects ERP XL: from 2020.2.2 through 2023.2.
0
Attacker Value
Unknown
CVE-2024-22291
Disclosure Date: January 31, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3.
0
Attacker Value
Unknown
CVE-2022-1618
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads
0
Attacker Value
Unknown
CVE-2023-40954
Disclosure Date: December 15, 2023 (last updated February 25, 2025)
A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.
0