Show filters
68 Total Results
Displaying 61-68 of 68
Sort by:
Attacker Value
Unknown
CVE-2021-24484
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
0
Attacker Value
Unknown
CVE-2021-24456
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard
0
Attacker Value
Unknown
CVE-2021-24459
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
0
Attacker Value
Unknown
CVE-2021-24461
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
0
Attacker Value
Unknown
CVE-2021-24462
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
0
Attacker Value
Unknown
CVE-2021-34635
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.8.
0
Attacker Value
Unknown
CVE-2016-10921
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
0
Attacker Value
Unknown
CVE-2014-7788
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Best Free Giveaways (aka com.wIphone5GiveAways) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0