Show filters
126 Total Results
Displaying 31-40 of 126
Sort by:
Attacker Value
Unknown
CVE-2023-25062
Disclosure Date: April 06, 2023 (last updated November 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.2.8 versions.
0
Attacker Value
Unknown
CVE-2023-28666
Disclosure Date: March 22, 2023 (last updated October 08, 2023)
The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user.
0
Attacker Value
Unknown
CVE-2023-0935
Disclosure Date: February 21, 2023 (last updated October 08, 2023)
A vulnerability was found in DolphinPHP up to 1.5.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file common.php of the component Incomplete Fix CVE-2021-46097. The manipulation of the argument id leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221551.
0
Attacker Value
Unknown
CVE-2023-0220
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.
0
Attacker Value
Unknown
CVE-2022-4063
Disclosure Date: December 19, 2022 (last updated February 24, 2025)
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
0
Attacker Value
Unknown
CVE-2022-41839
Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.
0
Attacker Value
Unknown
CVE-2022-2762
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-43407
Disclosure Date: October 19, 2022 (last updated February 24, 2025)
Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, which is used for the URLs that process user interactions for the given 'input' step (proceed or abort) and is not correctly encoded, allowing attackers able to configure Pipelines to have Jenkins build URLs from 'input' step IDs that would bypass the CSRF protection of any target URL in Jenkins when the 'input' step is interacted with.
0
Attacker Value
Unknown
CVE-2022-1602
Disclosure Date: September 13, 2022 (last updated October 08, 2023)
A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service Pack 9 (SP9). HP has released Service Pack 10 (SP10) to remediate the potential vulnerability introduced in SP8.
0
Attacker Value
Unknown
CVE-2022-37254
Disclosure Date: August 19, 2022 (last updated February 24, 2025)
DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configuration management.
0