Show filters
72 Total Results
Displaying 21-30 of 72
Sort by:
Attacker Value
Unknown

CVE-2024-0614

Disclosure Date: March 13, 2024 (last updated January 24, 2025)
The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Attacker Value
Unknown

CVE-2022-40361

Disclosure Date: January 11, 2024 (last updated January 17, 2024)
Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.
Attacker Value
Unknown

CVE-2023-48326

Disclosure Date: November 30, 2023 (last updated October 09, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.
Attacker Value
Unknown

CVE-2023-42331

Disclosure Date: September 20, 2023 (last updated October 09, 2023)
A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.
Attacker Value
Unknown

CVE-2023-28701

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system commands, disrupt service or terminate service.
Attacker Value
Unknown

CVE-2022-3891

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
Attacker Value
Unknown

CVE-2022-30816

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php.
Attacker Value
Unknown

CVE-2022-30815

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar=
Attacker Value
Unknown

CVE-2022-30814

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.
Attacker Value
Unknown

CVE-2022-30813

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.