Show filters
95 Total Results
Displaying 21-30 of 95
Sort by:
Attacker Value
Unknown

CVE-2022-4682

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-48006

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php.
Attacker Value
Unknown

CVE-2022-46998

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF).
Attacker Value
Unknown

CVE-2022-4324

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.
Attacker Value
Unknown

CVE-2022-32174

Disclosure Date: October 11, 2022 (last updated October 08, 2023)
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
Attacker Value
Unknown

CVE-2022-36261

Disclosure Date: August 23, 2022 (last updated October 08, 2023)
An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?action=file&ctrl=del&path=/../../../test.txt
Attacker Value
Unknown

CVE-2022-31262

Disclosure Date: August 17, 2022 (last updated November 29, 2024)
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.
Attacker Value
Unknown

CVE-2022-36262

Disclosure Date: August 15, 2022 (last updated October 08, 2023)
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
Attacker Value
Unknown

CVE-2021-44915

Disclosure Date: July 05, 2022 (last updated October 07, 2023)
Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
Attacker Value
Unknown

CVE-2022-31038

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved in commit 155cae1d which sanitizes `DisplayName` prior to display to the user. All users of gogs are advised to upgrade. Users unable to upgrade should check their users' display names for malicious characters.