Show filters
519 Total Results
Displaying 231-240 of 519
Sort by:
Attacker Value
Unknown
CVE-2023-43326
Disclosure Date: September 25, 2023 (last updated February 25, 2025)
A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.
0
Attacker Value
Unknown
CVE-2023-40869
Disclosure Date: September 14, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via a crafted script to the edit_menu, copuon, and group_categorias functions.
0
Attacker Value
Unknown
CVE-2023-40868
Disclosure Date: September 14, 2023 (last updated February 25, 2025)
Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Account and Deactivate functions.
0
Attacker Value
Unknown
CVE-2023-40554
Disclosure Date: September 06, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 versions.
0
Attacker Value
Unknown
CVE-2023-4773
Disclosure Date: September 06, 2023 (last updated October 08, 2023)
The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wordpress_social_login_meta' shortcode in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-25044
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions.
0
Attacker Value
Unknown
CVE-2023-24412
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Image Social Feed plugin <= 1.7.6 versions.
0
Attacker Value
Unknown
CVE-2023-34172
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions.
0
Attacker Value
Unknown
CVE-2023-34023
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions.
0
Attacker Value
Unknown
CVE-2023-3936
Disclosure Date: August 21, 2023 (last updated October 08, 2023)
The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0