Show filters
897 Total Results
Displaying 301-310 of 897
Sort by:
Attacker Value
Unknown
CVE-2023-5339
Disclosure Date: October 17, 2023 (last updated February 25, 2025)
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
0
Attacker Value
Unknown
CVE-2023-5057
Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks
0
Attacker Value
Unknown
CVE-2023-4725
Disclosure Date: October 16, 2023 (last updated October 20, 2023)
The Simple Posts Ticker WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2023-4646
Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2023-3746
Disclosure Date: October 16, 2023 (last updated October 19, 2023)
The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2023-3707
Disclosure Date: October 16, 2023 (last updated October 19, 2023)
The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected by this issue.
0
Attacker Value
Unknown
CVE-2023-3706
Disclosure Date: October 16, 2023 (last updated October 19, 2023)
The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector
0
Attacker Value
Unknown
CVE-2023-45273
Disclosure Date: October 16, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions.
0
Attacker Value
Unknown
CVE-2023-5333
Disclosure Date: October 09, 2023 (last updated February 25, 2025)
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
0
Attacker Value
Unknown
CVE-2023-5331
Disclosure Date: October 09, 2023 (last updated February 25, 2025)
Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.
0