Show filters
180 Total Results
Displaying 81-90 of 180
Sort by:
Attacker Value
Unknown
CVE-2023-24521
Disclosure Date: February 14, 2023 (last updated February 24, 2025)
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.
0
Attacker Value
Unknown
CVE-2022-4488
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-4776
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-4508
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-4483
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2022-4394
Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2022-3244
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce
0
Attacker Value
Unknown
CVE-2022-3243
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2022-37611
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.
0
Attacker Value
Unknown
CVE-2022-36341
Disclosure Date: August 10, 2022 (last updated February 24, 2025)
Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS – Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress.
0