Show filters
77 Total Results
Displaying 51-60 of 77
Sort by:
Attacker Value
Unknown

CVE-2019-19109

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
Attacker Value
Unknown

CVE-2019-19111

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.
Attacker Value
Unknown

CVE-2019-19110

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
Attacker Value
Unknown

CVE-2018-16613

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.
0
Attacker Value
Unknown

CVE-2018-12702

Disclosure Date: June 25, 2018 (last updated November 26, 2024)
The approveAndCallcode function of a smart contract implementation for Globalvillage ecosystem (GVE), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not verified, aka the "evilReflex" issue. NOTE: a PeckShield disclosure states "some researchers have independently discussed the mechanism of such vulnerability."
0
Attacker Value
Unknown

CVE-2018-11709

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
0
Attacker Value
Unknown

CVE-2018-11515

Disclosure Date: May 28, 2018 (last updated November 26, 2024)
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
0
Attacker Value
Unknown

CVE-2017-6393

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown

CVE-2008-2412

Disclosure Date: May 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2008-2413

Disclosure Date: May 22, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0