Show filters
266 Total Results
Displaying 41-50 of 266
Sort by:
Attacker Value
Unknown

CVE-2024-20868

Disclosure Date: May 07, 2024 (last updated May 07, 2024)
Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.
0
Attacker Value
Unknown

CVE-2024-31935

Disclosure Date: April 11, 2024 (last updated April 12, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6.
0
Attacker Value
Unknown

CVE-2024-3216

Disclosure Date: April 06, 2024 (last updated February 12, 2025)
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated attackers to reset all of the plugin's settings.
0
Attacker Value
Unknown

CVE-2024-22288

Disclosure Date: March 27, 2024 (last updated February 11, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.4.0.
Attacker Value
Unknown

CVE-2024-0957

Disclosure Date: March 22, 2024 (last updated February 12, 2025)
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected invoice for printing.
0
Attacker Value
Unknown

CVE-2023-7198

Disclosure Date: February 27, 2024 (last updated February 27, 2024)
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.
0
Attacker Value
Unknown

CVE-2023-6633

Disclosure Date: January 29, 2024 (last updated February 03, 2024)
The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in users perform unwanted actions, such as deleting administration notes, via CSRF attacks
Attacker Value
Unknown

CVE-2023-0479

Disclosure Date: January 16, 2024 (last updated January 23, 2024)
The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.
Attacker Value
Unknown

CVE-2023-7068

Disclosure Date: January 03, 2024 (last updated January 10, 2024)
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to export orders which can contain sensitive information.
Attacker Value
Unknown

CVE-2023-7130

Disclosure Date: December 31, 2023 (last updated January 06, 2024)
A vulnerability has been found in code-projects College Notes Gallery 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument user leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249133 was assigned to this vulnerability.