Show filters
64 Total Results
Displaying 41-50 of 64
Sort by:
Attacker Value
Unknown
CVE-2021-24626
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL Injection
0
Attacker Value
Unknown
CVE-2021-33587
Disclosure Date: May 28, 2021 (last updated November 28, 2024)
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.
0
Attacker Value
Unknown
CVE-2021-23382
Disclosure Date: April 26, 2021 (last updated February 22, 2025)
The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).
0
Attacker Value
Unknown
CVE-2021-23368
Disclosure Date: April 12, 2021 (last updated November 08, 2023)
The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
0
Attacker Value
Unknown
CVE-2020-28688
Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
0
Attacker Value
Unknown
CVE-2020-28687
Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
0
Attacker Value
Unknown
CVE-2020-4070
Disclosure Date: June 22, 2020 (last updated February 21, 2025)
In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
0
Attacker Value
Unknown
CVE-2020-13756
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.
0
Attacker Value
Unknown
CVE-2020-7601
Disclosure Date: March 15, 2020 (last updated February 21, 2025)
gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.
0
Attacker Value
Unknown
CVE-2019-5984
Disclosure Date: July 05, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0