Show filters
50 Total Results
Displaying 41-50 of 50
Sort by:
Attacker Value
Unknown

CVE-2022-24108

Disclosure Date: May 17, 2022 (last updated October 07, 2023)
The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code execution because of deserialization of untrusted data.
Attacker Value
Unknown

CVE-2021-36893

Disclosure Date: April 11, 2022 (last updated October 07, 2023)
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
Attacker Value
Unknown

CVE-2022-0621

Disclosure Date: March 28, 2022 (last updated October 07, 2023)
The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Attacker Value
Unknown

CVE-2012-1637

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.
Attacker Value
Unknown

CVE-2018-20555

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.
0
Attacker Value
Unknown

CVE-2018-5312

Disclosure Date: January 09, 2018 (last updated November 26, 2024)
The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php.
0
Attacker Value
Unknown

CVE-2015-4373

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes posted in an Organic Groups group.
0
Attacker Value
Unknown

CVE-2014-4531

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in main_page.php in the Game tabs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the n parameter.
0
Attacker Value
Unknown

CVE-2013-4406

Disclosure Date: May 19, 2014 (last updated October 05, 2023)
The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block permissions, which allows remote attackers to obtain sensitive information by reading a Quick Tab.
0
Attacker Value
Unknown

CVE-2008-2772

Disclosure Date: June 18, 2008 (last updated October 04, 2023)
The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote attackers to execute arbitrary PHP code via unspecified URL arguments, possibly related to a missing "whitelist of callbacks."
0