Show filters
72 Total Results
Displaying 21-30 of 72
Sort by:
Attacker Value
Unknown
CVE-2024-0614
Disclosure Date: March 13, 2024 (last updated January 24, 2025)
The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2022-40361
Disclosure Date: January 11, 2024 (last updated January 17, 2024)
Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.
0
Attacker Value
Unknown
CVE-2023-48326
Disclosure Date: November 30, 2023 (last updated October 09, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.
0
Attacker Value
Unknown
CVE-2023-42331
Disclosure Date: September 20, 2023 (last updated October 09, 2023)
A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.
0
Attacker Value
Unknown
CVE-2023-28701
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system commands, disrupt service or terminate service.
0
Attacker Value
Unknown
CVE-2022-3891
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
0
Attacker Value
Unknown
CVE-2022-30816
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php.
0
Attacker Value
Unknown
CVE-2022-30815
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar=
0
Attacker Value
Unknown
CVE-2022-30814
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.
0
Attacker Value
Unknown
CVE-2022-30813
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.
0