Show filters
278 Total Results
Displaying 241-250 of 278
Sort by:
Attacker Value
Unknown

CVE-2023-27925

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
Attacker Value
Unknown

CVE-2023-27923

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
Attacker Value
Unknown

CVE-2023-30189

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
Attacker Value
Unknown

CVE-2023-22355

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-22713

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
Attacker Value
Unknown

CVE-2023-1911

Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
Attacker Value
Unknown

CVE-2023-23898

Disclosure Date: April 06, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.
Attacker Value
Unknown

CVE-2023-0484

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Attacker Value
Unknown

CVE-2023-0441

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.
Attacker Value
Unknown

CVE-2023-22707

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.