Show filters
897 Total Results
Displaying 301-310 of 897
Sort by:
Attacker Value
Unknown

CVE-2023-5339

Disclosure Date: October 17, 2023 (last updated February 25, 2025)
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 
Attacker Value
Unknown

CVE-2023-5057

Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks
Attacker Value
Unknown

CVE-2023-4725

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
The Simple Posts Ticker WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2023-4646

Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2023-3746

Disclosure Date: October 16, 2023 (last updated October 19, 2023)
The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2023-3707

Disclosure Date: October 16, 2023 (last updated October 19, 2023)
The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected by this issue.
Attacker Value
Unknown

CVE-2023-3706

Disclosure Date: October 16, 2023 (last updated October 19, 2023)
The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector
Attacker Value
Unknown

CVE-2023-45273

Disclosure Date: October 16, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions.
Attacker Value
Unknown

CVE-2023-5333

Disclosure Date: October 09, 2023 (last updated February 25, 2025)
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
Attacker Value
Unknown

CVE-2023-5331

Disclosure Date: October 09, 2023 (last updated February 25, 2025)
Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.