Show filters
636 Total Results
Displaying 51-60 of 636
Sort by:
Attacker Value
Unknown

CVE-2022-40206

Disclosure Date: November 26, 2022 (last updated February 24, 2025)
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public.
Attacker Value
Unknown

CVE-2022-40192

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Attacker Value
Unknown

CVE-2022-40200

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Attacker Value
Unknown

CVE-2022-40632

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
Attacker Value
Unknown

CVE-2022-40205

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.
Attacker Value
Unknown

CVE-2022-38144

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.
Attacker Value
Unknown

CVE-2022-31501

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-31854

Disclosure Date: July 07, 2022 (last updated February 24, 2025)
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.
Attacker Value
Unknown

CVE-2017-20106

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-31296

Disclosure Date: June 17, 2022 (last updated February 23, 2025)
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.