Show filters
54 Total Results
Displaying 31-40 of 54
Sort by:
Attacker Value
Unknown
CVE-2022-25523
Disclosure Date: March 25, 2022 (last updated October 07, 2023)
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
0
Attacker Value
Unknown
CVE-2022-0360
Disclosure Date: February 28, 2022 (last updated October 07, 2023)
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2021-24936
Disclosure Date: January 24, 2022 (last updated October 07, 2023)
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2021-24752
Disclosure Date: October 18, 2021 (last updated November 28, 2024)
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before 1.7, Catch Scroll Progress Bar WordPress plugin before 1.6, Social Gallery and Widget WordPress plugin before 2.3, Catch Infinite Scroll WordPress plugin before 1.9, Catch Import Export WordPress plugin before 1.9, Catch Gallery WordPress plugin before 1.7, Catch Duplicate Switcher WordPress plugin before 1.6, Catch Breadcrumb WordPress plugin before 1.7, Catch IDs WordPres…
0
Attacker Value
Unknown
CVE-2020-19511
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
0
Attacker Value
Unknown
CVE-2020-35126
Disclosure Date: December 11, 2020 (last updated February 22, 2025)
Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy.
0
Attacker Value
Unknown
CVE-2020-25790
Disclosure Date: September 19, 2020 (last updated February 22, 2025)
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our security policy" and is being fixed for 5.2
0
Attacker Value
Unknown
CVE-2020-1416
Disclosure Date: July 14, 2020 (last updated February 21, 2025)
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
0
Attacker Value
Unknown
CVE-2019-18413
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input. NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product.
0
Attacker Value
Unknown
CVE-2018-20967
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
0