Show filters
898 Total Results
Displaying 241-250 of 898
Sort by:
Attacker Value
Unknown

CVE-2023-47876

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Perfmatters allows Reflected XSS.This issue affects Perfmatters: from n/a through 2.1.6.
Attacker Value
Unknown

CVE-2023-47875

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Perfmatters allows Cross Site Request Forgery.This issue affects Perfmatters: from n/a through 2.1.6.
Attacker Value
Unknown

CVE-2023-47777

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.
Attacker Value
Unknown

CVE-2023-45050

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed, & Growth allows Stored XSS.This issue affects Jetpack – WP Security, Backup, Speed, & Growth: from n/a through 12.8-a.1.
Attacker Value
Unknown

CVE-2023-5525

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
Attacker Value
Unknown

CVE-2023-6202

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
Attacker Value
Unknown

CVE-2023-48369

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.
Attacker Value
Unknown

CVE-2023-48268

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).
Attacker Value
Unknown

CVE-2023-47168

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
Attacker Value
Unknown

CVE-2023-45223

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled.