Show filters
101 Total Results
Displaying 71-80 of 101
Sort by:
Attacker Value
Unknown

CVE-2019-16251

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
Attacker Value
Unknown

CVE-2019-16282

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.
Attacker Value
Unknown

CVE-2019-17091

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
Attacker Value
Unknown

CVE-2016-11008

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
Attacker Value
Unknown

CVE-2016-11010

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
Attacker Value
Unknown

CVE-2016-11009

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
Attacker Value
Unknown

CVE-2016-11011

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
Attacker Value
Unknown

CVE-2016-11006

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
Attacker Value
Unknown

CVE-2016-11007

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
Attacker Value
Unknown

CVE-2019-10086

Disclosure Date: August 20, 2019 (last updated November 08, 2023)
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.