Show filters
61 Total Results
Displaying 41-50 of 61
Sort by:
Attacker Value
Unknown

CVE-2020-7104

Disclosure Date: January 17, 2020 (last updated February 21, 2025)
The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.
Attacker Value
Unknown

CVE-2015-9418

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.
Attacker Value
Unknown

CVE-2016-10892

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
0
Attacker Value
Unknown

CVE-2019-12345

Disclosure Date: May 27, 2019 (last updated November 27, 2024)
XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress.
0
Attacker Value
Unknown

CVE-2018-1002007

Disclosure Date: December 03, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request variable html_id.
0
Attacker Value
Unknown

CVE-2018-1002001

Disclosure Date: December 03, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
0
Attacker Value
Unknown

CVE-2018-1002002

Disclosure Date: December 03, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
0
Attacker Value
Unknown

CVE-2018-1002006

Disclosure Date: December 03, 2018 (last updated November 27, 2024)
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes
0
Attacker Value
Unknown

CVE-2018-1002008

Disclosure Date: December 03, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.
0
Attacker Value
Unknown

CVE-2018-1002000

Disclosure Date: December 03, 2018 (last updated November 27, 2024)
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.
0