Show filters
56 Total Results
Displaying 51-56 of 56
Sort by:
Attacker Value
Unknown

CVE-2021-24665

Disclosure Date: August 30, 2021 (last updated February 23, 2025)
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2016-10865

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
0
Attacker Value
Unknown

CVE-2017-2243

Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-9441

Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2) ll__opt[image2_url] or (3) ll__opt[image3_url] parameter in a ll_save_settings action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2010-0327

Disclosure Date: January 15, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the KJ: Imagelightbox (kj_imagelightbox2) extension 2.0.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-2490.
0
Attacker Value
Unknown

CVE-2008-2490

Disclosure Date: May 28, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2 (aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified "user input."
0