Show filters
733 Total Results
Displaying 201-210 of 733
Sort by:
Attacker Value
Unknown

CVE-2021-25049

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-25065

Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
Attacker Value
Unknown

CVE-2021-21408

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users should upgrade to version 3.1.43 or 4.0.3 to receive a patch.
Attacker Value
Unknown

CVE-2021-29454

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, external users could run arbitrary PHP code by crafting a malicious math string. Users should upgrade to version 3.1.42 or 4.0.2 to receive a patch.
Attacker Value
Unknown

CVE-2021-24918

Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
Attacker Value
Unknown

CVE-2021-43977

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS.
Attacker Value
Unknown

CVE-2021-32234

Disclosure Date: November 17, 2021 (last updated October 07, 2023)
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.
Attacker Value
Unknown

CVE-2021-42257

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression.
Attacker Value
Unknown

CVE-2020-23481

Disclosure Date: September 22, 2021 (last updated February 23, 2025)
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
Attacker Value
Unknown

CVE-2019-9060

Disclosure Date: September 17, 2021 (last updated February 23, 2025)
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).