Show filters
51 Total Results
Displaying 21-30 of 51
Sort by:
Attacker Value
Unknown

CVE-2023-23885

Disclosure Date: April 07, 2023 (last updated November 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.
Attacker Value
Unknown

CVE-2023-23979

Disclosure Date: April 06, 2023 (last updated November 08, 2023)
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 versions.
Attacker Value
Unknown

CVE-2022-46863

Disclosure Date: March 28, 2023 (last updated November 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions.
Attacker Value
Unknown

CVE-2023-23974

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update).
Attacker Value
Unknown

CVE-2023-23491

Disclosure Date: January 20, 2023 (last updated October 08, 2023)
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
Attacker Value
Unknown

CVE-2022-37339

Disclosure Date: September 02, 2022 (last updated February 24, 2025)
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress.
Attacker Value
Unknown

CVE-2022-1330

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .
Attacker Value
Unknown

CVE-2022-1295

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.
Attacker Value
Unknown

CVE-2021-24767

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack
Attacker Value
Unknown

CVE-2021-25791

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.