Show filters
64 Total Results
Displaying 31-40 of 64
Sort by:
Attacker Value
Unknown

CVE-2022-3768

Disclosure Date: November 28, 2022 (last updated February 24, 2025)
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
Attacker Value
Unknown

CVE-2021-40399

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
Attacker Value
Unknown

CVE-2022-24934

Disclosure Date: March 23, 2022 (last updated October 07, 2023)
wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.
Attacker Value
Unknown

CVE-2022-26511

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).
Attacker Value
Unknown

CVE-2022-26081

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.
Attacker Value
Unknown

CVE-2022-25969

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.
Attacker Value
Unknown

CVE-2022-25943

Disclosure Date: March 09, 2022 (last updated February 23, 2025)
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.
Attacker Value
Unknown

CVE-2021-24917

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
Attacker Value
Unknown

CVE-2021-24575

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.
Attacker Value
Unknown

CVE-2021-24664

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.