Show filters
64 Total Results
Displaying 51-60 of 64
Sort by:
Attacker Value
Unknown
CVE-2016-10916
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
0
Attacker Value
Unknown
CVE-2016-10909
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
0
Attacker Value
Unknown
CVE-2016-10908
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2019-14784
Disclosure Date: August 15, 2019 (last updated November 27, 2024)
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
0
Attacker Value
Unknown
CVE-2018-20964
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
0
Attacker Value
Unknown
CVE-2018-20963
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2019-14791
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
0
Attacker Value
Unknown
CVE-2019-14785
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
0
Attacker Value
Unknown
CVE-2019-9646
Disclosure Date: March 10, 2019 (last updated November 27, 2024)
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
0
Attacker Value
Unknown
CVE-2015-7666
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter.
0