Show filters
278 Total Results
Displaying 261-270 of 278
Sort by:
Attacker Value
Unknown

CVE-2021-24661

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.
Attacker Value
Unknown

CVE-2021-24659

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.
Attacker Value
Unknown

CVE-2021-24632

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-24660

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.
Attacker Value
Unknown

CVE-2021-24634

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2021-24667

Disclosure Date: August 30, 2021 (last updated February 23, 2025)
A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of image parameters in meta data.
Attacker Value
Unknown

CVE-2021-32789

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.
Attacker Value
Unknown

CVE-2021-24256

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Attacker Value
Unknown

CVE-2020-10814

Disclosure Date: April 08, 2020 (last updated February 21, 2025)
A buffer overflow vulnerability in Code::Blocks 17.12 allows an attacker to execute arbitrary code via a crafted project file.
Attacker Value
Unknown

CVE-2020-5549

Disclosure Date: April 08, 2020 (last updated February 21, 2025)
Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.