Show filters
182 Total Results
Displaying 51-60 of 182
Sort by:
Attacker Value
Unknown
CVE-2023-29387
Disclosure Date: August 18, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Julien Crego Manager for Icomoon plugin <= 2.0 versions.
0
Attacker Value
Unknown
CVE-2023-2592
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
0
Attacker Value
Unknown
CVE-2023-22717
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions.
0
Attacker Value
Unknown
CVE-2023-28821
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
0
Attacker Value
Unknown
CVE-2023-28820
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.
0
Attacker Value
Unknown
CVE-2023-28819
Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names.
0
Attacker Value
Unknown
CVE-2023-28477
Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.
0
Attacker Value
Unknown
CVE-2023-28476
Disclosure Date: April 28, 2023 (last updated January 09, 2024)
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.
0
Attacker Value
Unknown
CVE-2023-28475
Disclosure Date: April 28, 2023 (last updated December 06, 2023)
Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.
0
Attacker Value
Unknown
CVE-2023-28474
Disclosure Date: April 28, 2023 (last updated January 09, 2024)
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.
0