Show filters
85 Total Results
Displaying 21-30 of 85
Sort by:
Attacker Value
Unknown

CVE-2023-5662

Disclosure Date: November 22, 2023 (last updated November 29, 2023)
The Sponsors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sponsors' shortcode in all versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-31091

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.
Attacker Value
Unknown

CVE-2021-4315

Disclosure Date: January 28, 2023 (last updated October 08, 2023)
A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unknown code of the file psiturk/experiment.py. The manipulation of the argument mode leads to improper neutralization of special elements used in a template engine. The exploit has been disclosed to the public and may be used. Upgrading to version 3.2.1 is able to address this issue. The name of the patch is 47787e15cecd66f2aa87687bf852ae0194a4335f. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-219676.
Attacker Value
Unknown

CVE-2022-36357

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.
Attacker Value
Unknown

CVE-2022-1684

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin
Attacker Value
Unknown

CVE-2022-27308

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a project title.
Attacker Value
Unknown

CVE-2021-24398

Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query is ran twice.
Attacker Value
Unknown

CVE-2021-24726

Disclosure Date: September 13, 2021 (last updated February 23, 2025)
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
Attacker Value
Unknown

CVE-2020-15570

Disclosure Date: July 06, 2020 (last updated February 21, 2025)
The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to cause a denial of service via a malformed crash file.
Attacker Value
Unknown

CVE-2018-21245

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.