Show filters
80 Total Results
Displaying 21-30 of 80
Sort by:
Attacker Value
Unknown

CVE-2023-6984

Disclosure Date: January 03, 2024 (last updated February 25, 2025)
The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpack-lite-for-elementor/classes/class-pp-admin-settings.php file. This makes it possible for unauthenticated attackers to modify and reset plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-49739

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
[PROBLEMTYPE] in [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] on [PLATFORMS] allows [ATTACKER] to [IMPACT] via [VECTOR]
Attacker Value
Unknown

CVE-2023-2143

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2022-40274

Disclosure Date: September 30, 2022 (last updated October 08, 2023)
Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.
Attacker Value
Unknown

CVE-2022-34154

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
Attacker Value
Unknown

CVE-2022-36343

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
Attacker Value
Unknown

CVE-2022-31787

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO
Attacker Value
Unknown

CVE-2022-31786

Disclosure Date: June 21, 2022 (last updated February 23, 2025)
IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO.
Attacker Value
Unknown

CVE-2022-31788

Disclosure Date: June 10, 2022 (last updated February 23, 2025)
IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.
Attacker Value
Unknown

CVE-2022-27249

Disclosure Date: April 03, 2022 (last updated February 23, 2025)
An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.