Show filters
64 Total Results
Displaying 31-40 of 64
Sort by:
Attacker Value
Unknown
CVE-2023-44270
Disclosure Date: September 29, 2023 (last updated October 11, 2023)
An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.
0
Attacker Value
Unknown
CVE-2023-2482
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.
0
Attacker Value
Unknown
CVE-2022-33961
Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <= 7.5.8 versions.
0
Attacker Value
Unknown
CVE-2022-47154
Disclosure Date: March 14, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions.
0
Attacker Value
Unknown
CVE-2022-21222
Disclosure Date: September 30, 2022 (last updated February 24, 2025)
The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.
0
Attacker Value
Unknown
CVE-2022-25758
Disclosure Date: July 01, 2022 (last updated February 24, 2025)
All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.
0
Attacker Value
Unknown
CVE-2022-1960
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2021-24934
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-39318
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.
0