Show filters
152 Total Results
Displaying 21-30 of 152
Sort by:
Attacker Value
Unknown

CVE-2024-29220

Disclosure Date: April 11, 2024 (last updated April 11, 2024)
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
0
Attacker Value
Unknown

CVE-2024-26019

Disclosure Date: April 11, 2024 (last updated April 11, 2024)
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
0
Attacker Value
Unknown

CVE-2024-25572

Disclosure Date: April 11, 2024 (last updated April 11, 2024)
Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
0
Attacker Value
Unknown

CVE-2024-29814

Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Exchange Rates Widget allows Stored XSS.This issue affects Exchange Rates Widget: from n/a through 1.4.0.
0
Attacker Value
Unknown

CVE-2024-29930

Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.4.
0
Attacker Value
Unknown

CVE-2024-1723

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.58.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Affected parameters include: $instance['fonts']['title_options']['tag'], $headline_tag, $sub_headline_tag, $feature['icon'].
0
Attacker Value
Unknown

CVE-2023-49150

Disclosure Date: December 14, 2023 (last updated December 20, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.1.
Attacker Value
Unknown

CVE-2023-49149

Disclosure Date: December 14, 2023 (last updated December 20, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Currency Converter Calculator allows Stored XSS.This issue affects Currency Converter Calculator: from n/a through 1.3.1.
Attacker Value
Unknown

CVE-2020-24950

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.
Attacker Value
Unknown

CVE-2020-22153

Disclosure Date: July 03, 2023 (last updated October 08, 2023)
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.