Show filters
520 Total Results
Displaying 321-330 of 520
Sort by:
Attacker Value
Unknown
CVE-2022-0876
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2022-29419
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with a low role like a subscriber or higher.
0
Attacker Value
Unknown
CVE-2021-25120
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2022-0840
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2021-24987
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2022-27349
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-27348
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.
0
Attacker Value
Unknown
CVE-2021-39068
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215306.
0
Attacker Value
Unknown
CVE-2022-0887
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.
0
Attacker Value
Unknown
CVE-2021-24746
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.
0