Show filters
6,775 Total Results
Displaying 281-290 of 6,775
Sort by:
Attacker Value
Unknown

CVE-2024-11430

Disclosure Date: December 12, 2024 (last updated February 27, 2025)
The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' shortcode in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2024-21542

Disclosure Date: December 10, 2024 (last updated February 27, 2025)
Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.
0
Attacker Value
Unknown

CVE-2024-11205

Disclosure Date: December 10, 2024 (last updated February 27, 2025)
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.
Attacker Value
Unknown

CVE-2024-12369

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.
0
Attacker Value
Unknown

CVE-2024-54223

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Contact Form - Repute InfoSystems ARForms Form Builder allows Code Injection.This issue affects ARForms Form Builder: from n/a through 1.7.1.
0
Attacker Value
Unknown

CVE-2023-50903

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Wpmet Metform Elementor Contact Form Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform Elementor Contact Form Builder: from n/a through 3.4.0.
0
Attacker Value
Unknown

CVE-2023-50899

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2.
0
Attacker Value
Unknown

CVE-2023-50876

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Molongui Molongui allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Molongui: from n/a through 4.7.3.
0
Attacker Value
Unknown

CVE-2023-49154

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Wow-Company Button Generator – easily Button Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8.
0
Attacker Value
Unknown

CVE-2023-48750

Disclosure Date: December 09, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.1.10.
0