Show filters
72 Total Results
Displaying 31-40 of 72
Sort by:
Attacker Value
Unknown
CVE-2021-41790
Disclosure Date: October 21, 2021 (last updated February 23, 2025)
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.
0
Attacker Value
Unknown
CVE-2021-40927
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.
0
Attacker Value
Unknown
CVE-2021-24437
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.
0
Attacker Value
Unknown
CVE-2021-31783
Disclosure Date: April 26, 2021 (last updated February 22, 2025)
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
0
Attacker Value
Unknown
CVE-2020-12873
Disclosure Date: February 19, 2021 (last updated February 22, 2025)
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.
0
Attacker Value
Unknown
CVE-2020-5294
Disclosure Date: April 16, 2020 (last updated February 21, 2025)
PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0
0
Attacker Value
Unknown
CVE-2020-8777
Disclosure Date: March 02, 2020 (last updated February 21, 2025)
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
0
Attacker Value
Unknown
CVE-2020-8776
Disclosure Date: March 02, 2020 (last updated February 21, 2025)
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.
0
Attacker Value
Unknown
CVE-2020-8778
Disclosure Date: March 02, 2020 (last updated February 21, 2025)
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.
0
Attacker Value
Unknown
CVE-2019-19496
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
0