Show filters
733 Total Results
Displaying 211-220 of 733
Sort by:
Attacker Value
Unknown

CVE-2021-24508

Disclosure Date: September 13, 2021 (last updated February 23, 2025)
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.
Attacker Value
Unknown

CVE-2021-38324

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.
Attacker Value
Unknown

CVE-2021-40377

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.
Attacker Value
Unknown

CVE-2021-37538

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.
Attacker Value
Unknown

CVE-2020-29548

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session.
Attacker Value
Unknown

CVE-2021-38315

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in the ~/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.25.
Attacker Value
Unknown

CVE-2020-22732

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
Attacker Value
Unknown

CVE-2020-23241

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
Attacker Value
Unknown

CVE-2020-23240

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
Attacker Value
Unknown

CVE-2021-35440

Disclosure Date: July 06, 2021 (last updated February 22, 2025)
Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaScript on the victim's computer. The JavaScript code can then steal data available in the session/cookies depending on the user environment (e.g. if re-using internal URL's for deploying, or cookies that are very permissive) private information may be retrieved by the attacker.