Show filters
50 Total Results
Displaying 41-50 of 50
Sort by:
Attacker Value
Unknown
CVE-2023-0173
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2022-46147
Disclosure Date: November 28, 2022 (last updated February 24, 2025)
Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this issue. There are no known workarounds.
0
Attacker Value
Unknown
CVE-2022-3282
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
0
Attacker Value
Unknown
CVE-2022-1569
Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2022-0595
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2012-4479
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-4476
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-4472
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.
0
Attacker Value
Unknown
CVE-2012-4478
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication of administrators.
0
Attacker Value
Unknown
CVE-2012-4477
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors.
0