Show filters
198 Total Results
Displaying 41-50 of 198
Sort by:
Attacker Value
Unknown
CVE-2022-41609
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress.
0
Attacker Value
Unknown
CVE-2022-33142
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.
0
Attacker Value
Unknown
CVE-2017-20128
Disclosure Date: July 13, 2022 (last updated February 24, 2025)
A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2021-44097
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.
0
Attacker Value
Unknown
CVE-2022-29442
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress.
0
Attacker Value
Unknown
CVE-2022-29441
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages.
0
Attacker Value
Unknown
CVE-2021-35487
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data.
0
Attacker Value
Unknown
CVE-2022-29454
Disclosure Date: January 18, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.
0
Attacker Value
Unknown
CVE-2022-36389
Disclosure Date: January 18, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress.
0
Attacker Value
Unknown
CVE-2021-45693
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations.
0