Show filters
356 Total Results
Displaying 51-60 of 356
Sort by:
Attacker Value
Unknown
CVE-2024-2538
Disclosure Date: March 20, 2024 (last updated February 06, 2025)
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1. This makes it possible for authenticated attackers, with author access and above, to modify the permalinks of arbitrary posts.
0
Attacker Value
Unknown
CVE-2024-29092
Disclosure Date: March 19, 2024 (last updated February 06, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.
0
Attacker Value
Unknown
CVE-2024-0614
Disclosure Date: March 13, 2024 (last updated January 24, 2025)
The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2023-52223
Disclosure Date: February 28, 2024 (last updated February 29, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.
0
Attacker Value
Unknown
CVE-2024-25678
Disclosure Date: February 09, 2024 (last updated February 16, 2024)
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
0
Attacker Value
Unknown
CVE-2024-0232
Disclosure Date: January 16, 2024 (last updated April 25, 2024)
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
0
Attacker Value
Unknown
CVE-2023-4372
Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-40361
Disclosure Date: January 11, 2024 (last updated January 17, 2024)
Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.
0
Attacker Value
Unknown
CVE-2023-7104
Disclosure Date: December 29, 2023 (last updated January 09, 2024)
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.
0
Attacker Value
Unknown
CVE-2023-48326
Disclosure Date: November 30, 2023 (last updated October 09, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.
0