Show filters
733 Total Results
Displaying 201-210 of 733
Sort by:
Attacker Value
Unknown
CVE-2021-25049
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-25065
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
0
Attacker Value
Unknown
CVE-2021-21408
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users should upgrade to version 3.1.43 or 4.0.3 to receive a patch.
0
Attacker Value
Unknown
CVE-2021-29454
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, external users could run arbitrary PHP code by crafting a malicious math string. Users should upgrade to version 3.1.42 or 4.0.2 to receive a patch.
0
Attacker Value
Unknown
CVE-2021-24918
Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
0
Attacker Value
Unknown
CVE-2021-43977
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS.
0
Attacker Value
Unknown
CVE-2021-32234
Disclosure Date: November 17, 2021 (last updated October 07, 2023)
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.
0
Attacker Value
Unknown
CVE-2021-42257
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression.
0
Attacker Value
Unknown
CVE-2020-23481
Disclosure Date: September 22, 2021 (last updated February 23, 2025)
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
0
Attacker Value
Unknown
CVE-2019-9060
Disclosure Date: September 17, 2021 (last updated February 23, 2025)
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).
0