Show filters
101 Total Results
Displaying 71-80 of 101
Sort by:
Attacker Value
Unknown
CVE-2019-16251
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
0
Attacker Value
Unknown
CVE-2019-16282
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.
0
Attacker Value
Unknown
CVE-2019-17091
Disclosure Date: October 02, 2019 (last updated November 27, 2024)
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
0
Attacker Value
Unknown
CVE-2016-11008
Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
0
Attacker Value
Unknown
CVE-2016-11010
Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
0
Attacker Value
Unknown
CVE-2016-11009
Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
0
Attacker Value
Unknown
CVE-2016-11011
Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
0
Attacker Value
Unknown
CVE-2016-11006
Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
0
Attacker Value
Unknown
CVE-2016-11007
Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
0
Attacker Value
Unknown
CVE-2019-10086
Disclosure Date: August 20, 2019 (last updated November 08, 2023)
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
0