Show filters
543 Total Results
Displaying 61-70 of 543
Sort by:
Attacker Value
Unknown
CVE-2023-27421
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Everest News theme <= 1.1.0 versions.
0
Attacker Value
Unknown
CVE-2023-3537
Disclosure Date: July 07, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in SimplePHPscripts News Script PHP Pro 2.4. This affects an unknown part of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-233289 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-25052
Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa Yandex.News Feed by Teplitsa plugin <= 1.12.5 versions.
0
Attacker Value
Unknown
CVE-2023-1962
Disclosure Date: April 09, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225361 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-0502
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
0
Attacker Value
Unknown
CVE-2023-0785
Disclosure Date: February 12, 2023 (last updated February 16, 2024)
A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-220645 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-0784
Disclosure Date: February 12, 2023 (last updated October 08, 2023)
A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220644.
0
Attacker Value
Unknown
CVE-2022-4792
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
0
Attacker Value
Unknown
CVE-2020-36633
Disclosure Date: December 27, 2022 (last updated October 08, 2023)
A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this issue. The name of the patch is cd18d8b1afe464ae6626832496f4e070bac4c58f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216879.
0
Attacker Value
Unknown
CVE-2022-40694
Disclosure Date: November 17, 2022 (last updated December 22, 2024)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.
0