Show filters
292 Total Results
Displaying 241-250 of 292
Sort by:
Attacker Value
Unknown

CVE-2021-24331

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them
Attacker Value
Unknown

CVE-2021-24287

Disclosure Date: May 14, 2021 (last updated February 22, 2025)
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-24150

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
Attacker Value
Unknown

CVE-2020-29043

Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.
Attacker Value
Unknown

CVE-2020-29042

Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
Attacker Value
Unknown

CVE-2020-28954

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
Attacker Value
Unknown

CVE-2020-28953

Disclosure Date: November 19, 2020 (last updated November 28, 2024)
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
Attacker Value
Unknown

CVE-2020-27604

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.
Attacker Value
Unknown

CVE-2020-27611

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
Attacker Value
Unknown

CVE-2020-27605

Disclosure Date: October 21, 2020 (last updated February 22, 2025)
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."