Show filters
51 Total Results
Displaying 41-50 of 51
Sort by:
Attacker Value
Unknown

CVE-2020-13640

Disclosure Date: June 18, 2020 (last updated February 21, 2025)
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
Attacker Value
Unknown

CVE-2019-19112

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
Attacker Value
Unknown

CVE-2019-19109

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
Attacker Value
Unknown

CVE-2019-19111

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.
Attacker Value
Unknown

CVE-2019-19110

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
Attacker Value
Unknown

CVE-2019-19747

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).
Attacker Value
Unknown

CVE-2018-16613

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.
0
Attacker Value
Unknown

CVE-2018-11709

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
0
Attacker Value
Unknown

CVE-2018-11515

Disclosure Date: May 28, 2018 (last updated November 26, 2024)
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
0
Attacker Value
Unknown

CVE-2014-6754

Disclosure Date: September 28, 2014 (last updated October 05, 2023)
The Vector Outage Manager (aka nz.co.vector.outagemanager) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0