Show filters
120 Total Results
Displaying 71-80 of 120
Sort by:
Attacker Value
Unknown
CVE-2020-24313
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
0
Attacker Value
Unknown
CVE-2020-24312
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
0
Attacker Value
Unknown
CVE-2020-7107
Disclosure Date: January 16, 2020 (last updated February 21, 2025)
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
0
Attacker Value
Unknown
CVE-2019-17233
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
0
Attacker Value
Unknown
CVE-2019-17232
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
0
Attacker Value
Unknown
CVE-2015-9373
Disclosure Date: August 28, 2019 (last updated November 27, 2024)
PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
0
Attacker Value
Unknown
CVE-2019-15643
Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2018-14082
Disclosure Date: July 18, 2018 (last updated November 27, 2024)
PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar.
0
Attacker Value
Unknown
CVE-2017-16181
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
wintiwebdev is a static file server. wintiwebdev is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown
CVE-2016-10651
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
webdriver-launcher is a Node.js Selenium Webdriver Launcher. webdriver-launcher downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0