Show filters
543 Total Results
Displaying 81-90 of 543
Sort by:
Attacker Value
Unknown
CVE-2021-24342
Disclosure Date: June 07, 2021 (last updated February 22, 2025)
The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.
0
Attacker Value
Unknown
CVE-2020-29241
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter.
0
Attacker Value
Unknown
CVE-2020-29364
Disclosure Date: November 30, 2020 (last updated February 22, 2025)
In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news titles.
0
Attacker Value
Unknown
CVE-2020-25472
Disclosure Date: November 24, 2020 (last updated February 22, 2025)
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.
0
Attacker Value
Unknown
CVE-2020-25473
Disclosure Date: November 24, 2020 (last updated February 22, 2025)
SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies.
0
Attacker Value
Unknown
CVE-2020-25474
Disclosure Date: November 24, 2020 (last updated February 22, 2025)
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter.
0
Attacker Value
Unknown
CVE-2020-25475
Disclosure Date: November 24, 2020 (last updated February 22, 2025)
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
0
Attacker Value
Unknown
CVE-2020-26825
Disclosure Date: November 13, 2020 (last updated February 22, 2025)
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. Information maintained in the victim's web browser can be read, modified, and sent to the attacker. The malicious code cannot significantly impact the victim's browser and the victim can easily close the browser tab to terminate it.
0
Attacker Value
Unknown
CVE-2020-26815
Disclosure Date: November 10, 2020 (last updated February 22, 2025)
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.
0
Attacker Value
Unknown
CVE-2020-5558
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
0