Show filters
1,718 Total Results
Displaying 51-60 of 1,718
Sort by:
Attacker Value
Unknown

CVE-2024-12471

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due to a missing capability check and file type validation on the add_image_to_library AJAX action function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files that make remote code execution possible.
Attacker Value
Unknown

CVE-2024-10102

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown

CVE-2024-12327

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pblzbg_save_settings() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings.
Attacker Value
Unknown

CVE-2024-11445

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The Image Magnify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_magnify' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-12022

Disclosure Date: January 07, 2025 (last updated January 17, 2025)
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-52485. Reason: This candidate is a reservation duplicate of CVE-2024-52485. Notes: All CVE users should reference CVE-2024-52485 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Attacker Value
Unknown

CVE-2024-55538

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736.
0
Attacker Value
Unknown

CVE-2024-49385

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736.
0
Attacker Value
Unknown

CVE-2022-41995

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Galleryape Gallery Images Ape allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gallery Images Ape: from n/a through 2.2.8.
0
Attacker Value
Unknown

CVE-2023-45631

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
0
Attacker Value
Unknown

CVE-2024-56016

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPTooling Image Mapper allows Reflected XSS.This issue affects Image Mapper: from n/a through 0.2.5.3.
0