Show filters
93 Total Results
Displaying 61-70 of 93
Sort by:
Attacker Value
Unknown
CVE-2018-9861
Disclosure Date: April 19, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
0
Attacker Value
Unknown
CVE-2018-7422
Disclosure Date: March 19, 2018 (last updated November 26, 2024)
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute path traversal.
0
Attacker Value
Unknown
CVE-2017-15287
Disclosure Date: October 12, 2017 (last updated November 26, 2024)
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.
0
Attacker Value
Unknown
CVE-2017-9336
Disclosure Date: June 01, 2017 (last updated November 26, 2024)
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post.
0
Attacker Value
Unknown
CVE-2015-4455
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.
0
Attacker Value
Unknown
CVE-2017-6591
Disclosure Date: March 09, 2017 (last updated November 26, 2024)
There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.
0
Attacker Value
Unknown
CVE-2017-6589
Disclosure Date: March 09, 2017 (last updated November 26, 2024)
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.
0
Attacker Value
Unknown
CVE-2016-1000126
Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin admin-font-editor v1.8
0
Attacker Value
Unknown
CVE-2014-7652
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Magicam Photo Magic Editor (aka mobi.magicam.editor) application 5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7013
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Funny Photo Color Editor (aka com.doirdeditor.funcloreditor) application 0.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0