Show filters
1,937 Total Results
Displaying 31-40 of 1,937
Sort by:
Attacker Value
Unknown

CVE-2025-24739

Disclosure Date: January 24, 2025 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.
0
Attacker Value
Unknown

CVE-2025-24659

Disclosure Date: January 24, 2025 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WordPress Download Manager Premium Packages allows Blind SQL Injection. This issue affects Premium Packages: from n/a through 5.9.6.
0
Attacker Value
Unknown

CVE-2025-23636

Disclosure Date: January 23, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dimitar Atanasov My Favorite Car allows Reflected XSS. This issue affects My Favorite Car: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2025-23662

Disclosure Date: January 16, 2025 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Ryan Sutana WP Panoramio allows Stored XSS.This issue affects WP Panoramio: from n/a through 1.5.0.
0
Attacker Value
Unknown

CVE-2025-23661

Disclosure Date: January 16, 2025 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Ryan Sutana NV Slider allows Stored XSS.This issue affects NV Slider: from n/a through 1.6.
0
Attacker Value
Unknown

CVE-2024-10789

Disclosure Date: January 16, 2025 (last updated February 27, 2025)
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for unauthenticated attackers to update the plugins setting which controls access to the functionality via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-11386

Disclosure Date: January 11, 2025 (last updated February 27, 2025)
The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsmartform' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2025-22540

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sebastian Orellana Emailing Subscription allows Blind SQL Injection.This issue affects Emailing Subscription: from n/a through 1.4.1.
0
Attacker Value
Unknown

CVE-2024-11383

Disclosure Date: January 07, 2025 (last updated February 27, 2025)
The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cc-mortgage-canada' shortcode in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2022-45830

Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3.
0