Show filters
292 Total Results
Displaying 241-250 of 292
Sort by:
Attacker Value
Unknown
CVE-2021-24331
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them
0
Attacker Value
Unknown
CVE-2021-24287
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-24150
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
0
Attacker Value
Unknown
CVE-2020-29043
Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.
0
Attacker Value
Unknown
CVE-2020-29042
Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
0
Attacker Value
Unknown
CVE-2020-28954
Disclosure Date: November 19, 2020 (last updated February 22, 2025)
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
0
Attacker Value
Unknown
CVE-2020-28953
Disclosure Date: November 19, 2020 (last updated November 28, 2024)
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
0
Attacker Value
Unknown
CVE-2020-27604
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.
0
Attacker Value
Unknown
CVE-2020-27611
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
0
Attacker Value
Unknown
CVE-2020-27605
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."
0