Show filters
267 Total Results
Displaying 71-80 of 267
Sort by:
Attacker Value
Unknown

CVE-2023-6583

Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via the Recurring Import functionality. This makes it possible for authenticated attackers, with administrator access and above, to read and delete the contents of arbitrary files on the server including wp-config.php, which can contain sensitive information.
Attacker Value
Unknown

CVE-2023-6627

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.
Attacker Value
Unknown

CVE-2023-7212

Disclosure Date: January 07, 2024 (last updated January 12, 2024)
A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249768. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-40658

Disclosure Date: December 14, 2023 (last updated December 20, 2023)
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
Attacker Value
Unknown

CVE-2023-49494

Disclosure Date: December 11, 2023 (last updated December 14, 2023)
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.
Attacker Value
Unknown

CVE-2023-49493

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.
Attacker Value
Unknown

CVE-2023-49492

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.
Attacker Value
Unknown

CVE-2023-6011

Disclosure Date: November 22, 2023 (last updated January 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DECE Software Geodi allows Stored XSS.This issue affects Geodi: before 8.0.0.27396.
Attacker Value
Unknown

CVE-2023-5921

Disclosure Date: November 22, 2023 (last updated December 05, 2023)
Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass.This issue affects Geodi: before 8.0.0.27396.
Attacker Value
Unknown

CVE-2023-43275

Disclosure Date: November 16, 2023 (last updated November 21, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.