Show filters
95 Total Results
Displaying 21-30 of 95
Sort by:
Attacker Value
Unknown

CVE-2024-2027

Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its style attributes in all versions up to, and including, 4.22.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2023-34020

Disclosure Date: March 27, 2024 (last updated April 02, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.
0
Attacker Value
Unknown

CVE-2023-52151

Disclosure Date: January 05, 2024 (last updated January 10, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin: from n/a through 5.1.0.2.
Attacker Value
Unknown

CVE-2023-48124

Disclosure Date: November 21, 2023 (last updated November 30, 2023)
Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email and Address parameters in the Register New Account component.
Attacker Value
Unknown

CVE-2023-5802

Disclosure Date: October 26, 2023 (last updated October 31, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Mihai Iova WordPress Knowledge base & Documentation Plugin – WP Knowledgebase plugin <= 1.3.4 versions.
Attacker Value
Unknown

CVE-2023-40618

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'.
Attacker Value
Unknown

CVE-2023-40617

Disclosure Date: September 13, 2023 (last updated October 08, 2023)
A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'.
Attacker Value
Unknown

CVE-2023-23714

Disclosure Date: May 26, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash plugin <= 3.6.4.1 versions.
Attacker Value
Unknown

CVE-2023-0285

Disclosure Date: February 21, 2023 (last updated October 08, 2023)
The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2023-0253

Disclosure Date: February 02, 2023 (last updated August 06, 2024)
** REJECT ** **REJECT** Accidental CVE Assignment. Please use CVE-2023-0285.