Show filters
520 Total Results
Displaying 311-320 of 520
Sort by:
Attacker Value
Unknown

CVE-2022-33960

Disclosure Date: June 09, 2022 (last updated February 24, 2025)
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
Attacker Value
Unknown

CVE-2021-36890

Disclosure Date: May 27, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress.
Attacker Value
Unknown

CVE-2022-30460

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
Simple Social Networking Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /sns/classes/Users.php?f=save, firstname.
Attacker Value
Unknown

CVE-2022-1418

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.
Attacker Value
Unknown

CVE-2022-1062

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2022-30379

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.
Attacker Value
Unknown

CVE-2022-30378

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=.
Attacker Value
Unknown

CVE-2022-30376

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.
Attacker Value
Unknown

CVE-2022-30375

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.
Attacker Value
Unknown

CVE-2022-0874

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.