Show filters
120 Total Results
Displaying 71-80 of 120
Sort by:
Attacker Value
Unknown

CVE-2020-24313

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
Attacker Value
Unknown

CVE-2020-24312

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
Attacker Value
Unknown

CVE-2020-7107

Disclosure Date: January 16, 2020 (last updated February 21, 2025)
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
Attacker Value
Unknown

CVE-2019-17233

Disclosure Date: October 07, 2019 (last updated November 27, 2024)
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
Attacker Value
Unknown

CVE-2019-17232

Disclosure Date: October 07, 2019 (last updated November 27, 2024)
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
Attacker Value
Unknown

CVE-2015-9373

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
0
Attacker Value
Unknown

CVE-2019-15643

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2018-14082

Disclosure Date: July 18, 2018 (last updated November 27, 2024)
PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar.
0
Attacker Value
Unknown

CVE-2017-16181

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
wintiwebdev is a static file server. wintiwebdev is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2016-10651

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
webdriver-launcher is a Node.js Selenium Webdriver Launcher. webdriver-launcher downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0