Show filters
896 Total Results
Displaying 221-230 of 896
Sort by:
Attacker Value
Unknown

CVE-2023-32747

Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.
Attacker Value
Unknown

CVE-2023-35916

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
Attacker Value
Unknown

CVE-2023-35915

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
Attacker Value
Unknown

CVE-2023-35914

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a through 5.1.2.
Attacker Value
Unknown

CVE-2023-35876

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.
Attacker Value
Unknown

CVE-2023-37871

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
Attacker Value
Unknown

CVE-2023-47789

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a through 2.8.3.
Attacker Value
Unknown

CVE-2023-47787

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.
Attacker Value
Unknown

CVE-2023-49828

Disclosure Date: December 14, 2023 (last updated December 19, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.
Attacker Value
Unknown

CVE-2023-6727

Disclosure Date: December 12, 2023 (last updated December 16, 2023)
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked.