Show filters
44 Total Results
Displaying 41-44 of 44
Sort by:
Attacker Value
Unknown
CVE-2021-24464
Disclosure Date: August 02, 2021 (last updated November 28, 2024)
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2021-24442
Disclosure Date: July 12, 2021 (last updated November 28, 2024)
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks
0
Attacker Value
Unknown
CVE-2018-10363
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
0
Attacker Value
Unknown
CVE-2017-14125
Disclosure Date: September 25, 2017 (last updated November 26, 2024)
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
0