Show filters
77 Total Results
Displaying 21-30 of 77
Sort by:
Attacker Value
Unknown
CVE-2023-47775
Disclosure Date: November 22, 2023 (last updated November 28, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.
0
Attacker Value
Unknown
CVE-2023-47185
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.
0
Attacker Value
Unknown
CVE-2023-46287
Disclosure Date: October 20, 2023 (last updated October 27, 2023)
XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.
0
Attacker Value
Unknown
CVE-2023-3998
Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a post.
0
Attacker Value
Unknown
CVE-2023-3869
Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a comment.
0
Attacker Value
Unknown
CVE-2023-2309
Disclosure Date: July 24, 2023 (last updated October 08, 2023)
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
0
Attacker Value
Unknown
CVE-2023-33213
Disclosure Date: June 19, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin <= 1.3.0 versions.
0
Attacker Value
Unknown
CVE-2023-2249
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.
0
Attacker Value
Unknown
CVE-2023-33216
Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9.
0
Attacker Value
Unknown
CVE-2022-46945
Disclosure Date: May 26, 2023 (last updated November 04, 2023)
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
0