Show filters
89 Total Results
Displaying 61-70 of 89
Sort by:
Attacker Value
Unknown

CVE-2021-3938

Disclosure Date: November 13, 2021 (last updated February 23, 2025)
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-3931

Disclosure Date: November 13, 2021 (last updated February 23, 2025)
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2021-3863

Disclosure Date: October 19, 2021 (last updated February 23, 2025)
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-3879

Disclosure Date: October 19, 2021 (last updated February 23, 2025)
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-3858

Disclosure Date: October 19, 2021 (last updated February 23, 2025)
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2020-7845

Disclosure Date: December 27, 2020 (last updated February 22, 2025)
Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsing MAIL FROM command. It leads remote attacker to execute arbitrary code via crafted packet.
Attacker Value
Unknown

CVE-2020-8417

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
Attacker Value
Unknown

CVE-2019-16289

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
Attacker Value
Unknown

CVE-2019-15858

Disclosure Date: September 03, 2019 (last updated November 27, 2024)
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
Attacker Value
Unknown

CVE-2019-14773

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.
0