Show filters
461 Total Results
Displaying 201-210 of 461
Sort by:
Attacker Value
Unknown
CVE-2022-4747
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2023-0097
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2014-125051
Disclosure Date: January 06, 2023 (last updated February 24, 2025)
A vulnerability was found in himiklab yii2-jqgrid-widget up to 1.0.7. It has been declared as critical. This vulnerability affects the function addSearchOptionsRecursively of the file JqGridAction.php. The manipulation leads to sql injection. Upgrading to version 1.0.8 is able to address this issue. The name of the patch is a117e0f2df729e3ff726968794d9a5ac40e660b9. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217564.
0
Attacker Value
Unknown
CVE-2021-4262
Disclosure Date: December 19, 2022 (last updated February 24, 2025)
A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5bdb2681133036f935e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216271.
0
Attacker Value
Unknown
CVE-2022-41791
Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
0
Attacker Value
Unknown
CVE-2022-3578
Disclosure Date: November 14, 2022 (last updated February 24, 2025)
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-23458
Disclosure Date: September 22, 2022 (last updated February 24, 2025)
Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted content into editable cells. This issue was fixed in version 4.21.3. There are no known workarounds.
0
Attacker Value
Unknown
CVE-2022-2597
Disclosure Date: September 05, 2022 (last updated February 24, 2025)
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts
0
Attacker Value
Unknown
CVE-2022-2543
Disclosure Date: September 05, 2022 (last updated February 24, 2025)
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts
0
Attacker Value
Unknown
CVE-2022-1271
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
0