Show filters
133 Total Results
Displaying 41-50 of 133
Sort by:
Attacker Value
Unknown

CVE-2022-38141

Disclosure Date: January 17, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8.
Attacker Value
Unknown

CVE-2023-7075

Disclosure Date: December 22, 2023 (last updated February 25, 2025)
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /main/checkout.php. The manipulation of the argument pt leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248846 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-47533

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Countdown and CountUp, WooCommerce Sales Timer plugin <= 1.8.2 versions.
Attacker Value
Unknown

CVE-2023-32118

Disclosure Date: June 12, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPoperation SALERT – Fake Sales Notification WooCommerce plugin <= 1.2.1 versions.
Attacker Value
Unknown

CVE-2023-3184

Disclosure Date: June 09, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231164.
Attacker Value
Unknown

CVE-2023-1983

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/products/manage_product.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-225530 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-26773

Disclosure Date: April 10, 2023 (last updated February 24, 2025)
Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file.
Attacker Value
Unknown

CVE-2023-26774

Disclosure Date: April 10, 2023 (last updated October 08, 2023)
An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint.
Attacker Value
Unknown

CVE-2023-1087

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
Attacker Value
Unknown

CVE-2023-1363

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add User Account. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222870 is the identifier assigned to this vulnerability.