Show filters
50 Total Results
Displaying 41-50 of 50
Sort by:
Attacker Value
Unknown
CVE-2022-24108
Disclosure Date: May 17, 2022 (last updated October 07, 2023)
The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data.
0
Attacker Value
Unknown
CVE-2021-36893
Disclosure Date: April 11, 2022 (last updated October 07, 2023)
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
0
Attacker Value
Unknown
CVE-2022-0621
Disclosure Date: March 28, 2022 (last updated October 07, 2023)
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
0
Attacker Value
Unknown
CVE-2012-1637
Disclosure Date: November 21, 2019 (last updated November 27, 2024)
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.
0
Attacker Value
Unknown
CVE-2018-20555
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.
0
Attacker Value
Unknown
CVE-2018-5312
Disclosure Date: January 09, 2018 (last updated November 26, 2024)
The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php.
0
Attacker Value
Unknown
CVE-2015-4373
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes posted in an Organic Groups group.
0
Attacker Value
Unknown
CVE-2014-4531
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in main_page.php in the Game tabs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the n parameter.
0
Attacker Value
Unknown
CVE-2013-4406
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block permissions, which allows remote attackers to obtain sensitive information by reading a Quick Tab.
0
Attacker Value
Unknown
CVE-2008-2772
Disclosure Date: June 18, 2008 (last updated October 04, 2023)
The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote attackers to execute arbitrary PHP code via unspecified URL arguments, possibly related to a missing "whitelist of callbacks."
0