Show filters
50 Total Results
Displaying 41-50 of 50
Sort by:
Attacker Value
Unknown

CVE-2023-0173

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-46147

Disclosure Date: November 28, 2022 (last updated February 24, 2025)
Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this issue. There are no known workarounds.
Attacker Value
Unknown

CVE-2022-3282

Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.
Attacker Value
Unknown

CVE-2022-1569

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2022-0595

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2012-4479

Disclosure Date: November 30, 2012 (last updated October 05, 2023)
SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-4476

Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-4472

Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.
0
Attacker Value
Unknown

CVE-2012-4478

Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication of administrators.
0
Attacker Value
Unknown

CVE-2012-4477

Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors.
0