Show filters
93 Total Results
Displaying 51-60 of 93
Sort by:
Attacker Value
Unknown

CVE-2011-4972

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
Attacker Value
Unknown

CVE-2016-10877

Disclosure Date: August 12, 2019 (last updated November 27, 2024)
The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
0
Attacker Value
Unknown

CVE-2019-19466

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
SCEditor 2.1.3 allows XSS.
Attacker Value
Unknown

CVE-2019-14517

Disclosure Date: August 01, 2019 (last updated November 27, 2024)
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
0
Attacker Value
Unknown

CVE-2019-1010005

Disclosure Date: July 15, 2019 (last updated November 27, 2024)
HexoEditor v1.1.8-beta is affected by: XSS to code execution.
0
Attacker Value
Unknown

CVE-2018-17960

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
0
Attacker Value
Unknown

CVE-2018-18950

Disclosure Date: November 05, 2018 (last updated November 27, 2024)
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.
0
Attacker Value
Unknown

CVE-2018-18909

Disclosure Date: November 03, 2018 (last updated November 27, 2024)
xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code view.
0
Attacker Value
Unknown

CVE-2018-13184

Disclosure Date: July 05, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for TravelZedi Token (ZEDI), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown

CVE-2018-11093

Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.