Show filters
570 Total Results
Displaying 51-60 of 570
Sort by:
Attacker Value
Unknown

CVE-2023-6552

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.
Attacker Value
Unknown

CVE-2023-52132

Disclosure Date: December 31, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jewel Theme WP Adminify.This issue affects WP Adminify: from n/a through 3.1.6.
Attacker Value
Unknown

CVE-2023-50448

Disclosure Date: December 28, 2023 (last updated February 25, 2025)
In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times.
Attacker Value
Unknown

CVE-2023-51763

Disclosure Date: December 24, 2023 (last updated February 25, 2025)
csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.
Attacker Value
Unknown

CVE-2023-48966

Disclosure Date: December 04, 2023 (last updated February 25, 2025)
An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a crafted Zip file.
Attacker Value
Unknown

CVE-2023-48965

Disclosure Date: December 04, 2023 (last updated February 25, 2025)
An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malicious PHP file.
Attacker Value
Unknown

CVE-2023-38515

Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 3.7.56.
Attacker Value
Unknown

CVE-2023-40852

Disclosure Date: October 16, 2023 (last updated February 25, 2025)
SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.
Attacker Value
Unknown

CVE-2023-40851

Disclosure Date: October 16, 2023 (last updated February 25, 2025)
Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page.
Attacker Value
Unknown

CVE-2023-44266

Disclosure Date: October 02, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jewel Theme WP Adminify plugin <= 3.1.6 versions.