Show filters
82 Total Results
Displaying 51-60 of 82
Sort by:
Attacker Value
Unknown

CVE-2019-12566

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.
0
Attacker Value
Unknown

TIBCO Spotfire Statistics Services Exposes Sensitive Files

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database, JMX, LDAP, Windows service account, and user credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions up to and including 7.11.1; 10.0.0.
Attacker Value
Unknown

CVE-2019-10864

Disclosure Date: April 23, 2019 (last updated November 08, 2023)
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
0
Attacker Value
Unknown

TIBCO Spotfire Statistics Services remote execution vulnerabilities

Disclosure Date: October 10, 2018 (last updated November 27, 2024)
The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component. Affected releases are TIBCO Software Inc. TIBCO Spotfire Statistics Services versions up to and including 7.11.0.
0
Attacker Value
Unknown

CVE-2018-17074

Disclosure Date: September 16, 2018 (last updated November 27, 2024)
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
0
Attacker Value
Unknown

CVE-2018-1000556

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an URL with payload and send to the user. Victim need to open the link to be affected by reflected XSS. .
0
Attacker Value
Unknown

CVE-2018-11532

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
0
Attacker Value
Unknown

CVE-2017-10991

Disclosure Date: July 07, 2017 (last updated November 08, 2023)
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
0
Attacker Value
Unknown

CVE-2017-2136

Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
0
Attacker Value
Unknown

CVE-2017-2135

Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0