Show filters
898 Total Results
Displaying 241-250 of 898
Sort by:
Attacker Value
Unknown
CVE-2023-47876
Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Perfmatters allows Reflected XSS.This issue affects Perfmatters: from n/a through 2.1.6.
0
Attacker Value
Unknown
CVE-2023-47875
Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Perfmatters allows Cross Site Request Forgery.This issue affects Perfmatters: from n/a through 2.1.6.
0
Attacker Value
Unknown
CVE-2023-47777
Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.
0
Attacker Value
Unknown
CVE-2023-45050
Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed, & Growth allows Stored XSS.This issue affects Jetpack – WP Security, Backup, Speed, & Growth: from n/a through 12.8-a.1.
0
Attacker Value
Unknown
CVE-2023-5525
Disclosure Date: November 27, 2023 (last updated February 25, 2025)
The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
0
Attacker Value
Unknown
CVE-2023-6202
Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
0
Attacker Value
Unknown
CVE-2023-48369
Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.
0
Attacker Value
Unknown
CVE-2023-48268
Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).
0
Attacker Value
Unknown
CVE-2023-47168
Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
0
Attacker Value
Unknown
CVE-2023-45223
Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled.
0