Show filters
73 Total Results
Displaying 41-50 of 73
Sort by:
Attacker Value
Unknown

CVE-2021-24632

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-24634

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2020-9309

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the file contents. Uploads stored as protected or draft files are allowed by default for authorised users only, but can also be enabled through custom logic as well as modules such as silverstripe/userforms. Sites using the previously optional silverstripe/mimevalidator module can configure MIME whitelists rather than extension whitelists, and hence prevent this issue. Sites on the Common Web Platform (CWP) use this module by default, and are not affected.
Attacker Value
Unknown

CVE-2019-15836

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
0
Attacker Value
Unknown

CVE-2017-8940

Disclosure Date: May 15, 2017 (last updated November 08, 2023)
The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2016-1000147

Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin recipes-writer v1.0.4
0
Attacker Value
Unknown

CVE-2014-9440

Disclosure Date: January 02, 2015 (last updated October 05, 2023)
SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter.
0
Attacker Value
Unknown

CVE-2014-9347

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the words_exact parameter.
0
Attacker Value
Unknown

CVE-2014-7454

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Detox Juicing Diet Recipes (aka com.wDetoxJuicingDietRecipes) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7476

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Healthy Lunch Diet Recipes (aka com.best.lunchdietrecipes) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0