Show filters
463 Total Results
Displaying 61-70 of 463
Sort by:
Attacker Value
Unknown
CVE-2024-5993
Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_session' function in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the session token of the chatbot.
0
Attacker Value
Unknown
CVE-2024-5992
Disclosure Date: July 09, 2024 (last updated July 09, 2024)
The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_chatbot_token' and 'update_chatbot_position' functions in all versions up to, and including, 3.0.1. This makes it possible for unauthenticated attackers to change chatbot settings, which can lead to unavailability or other changes to the chatbot.
0
Attacker Value
Unknown
CVE-2024-3563
Disclosure Date: July 09, 2024 (last updated August 08, 2024)
The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-36038
Disclosure Date: June 24, 2024 (last updated June 25, 2024)
Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.
0
Attacker Value
Unknown
CVE-2024-4755
Disclosure Date: June 21, 2024 (last updated June 25, 2024)
The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2024-4873
Disclosure Date: June 19, 2024 (last updated January 05, 2025)
The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to replace images uploaded by higher level users such as admins.
0
Attacker Value
Unknown
CVE-2024-37625
Disclosure Date: June 17, 2024 (last updated July 19, 2024)
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.
0
Attacker Value
Unknown
CVE-2024-6039
Disclosure Date: June 16, 2024 (last updated August 20, 2024)
A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of the argument dim leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268752.
0
Attacker Value
Unknown
CVE-2024-38454
Disclosure Date: June 16, 2024 (last updated July 27, 2024)
ExpressionEngine before 7.4.11 allows XSS.
0
Attacker Value
Unknown
CVE-2024-34762
Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Vulnerability discovered by executing a planned security audit.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
0