Show filters
96 Total Results
Displaying 71-80 of 96
Sort by:
Attacker Value
Unknown

CVE-2014-6420

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture.
Attacker Value
Unknown

CVE-2014-4567

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.
Attacker Value
Unknown

CVE-2019-10416

Disclosure Date: September 25, 2019 (last updated October 26, 2023)
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
Attacker Value
Unknown

CVE-2019-10415

Disclosure Date: September 25, 2019 (last updated October 26, 2023)
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Attacker Value
Unknown

CVE-2017-18608

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.
Attacker Value
Unknown

CVE-2014-10382

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
0
Attacker Value
Unknown

CVE-2017-18561

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The embed-comment-images plugin before 0.6 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2018-11526

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
0
Attacker Value
Unknown

CVE-2014-2274

Disclosure Date: March 19, 2018 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/index.php page to wp-admin/admin.php.
0
Attacker Value
Unknown

CVE-2014-2550

Disclosure Date: March 19, 2018 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php.
0