Show filters
292 Total Results
Displaying 201-210 of 292
Sort by:
Attacker Value
Unknown
CVE-2020-27601
Disclosure Date: September 29, 2022 (last updated February 24, 2025)
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.
0
Attacker Value
Unknown
CVE-2021-36839
Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress.
0
Attacker Value
Unknown
CVE-2022-2709
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-2375
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2022-36346
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.
0
Attacker Value
Unknown
CVE-2022-38703
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress
0
Attacker Value
Unknown
CVE-2022-1912
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-31065
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript), the script gets executed. Additionally when the victim receives a notification that the attacker has left the session. This issue has been patched in version 2.4.8 and 2.5.0. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-31064
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has been addressed in version 2.4.8 and 2.5.0. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-1653
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.
0