Show filters
180 Total Results
Displaying 81-90 of 180
Sort by:
Attacker Value
Unknown

CVE-2023-24521

Disclosure Date: February 14, 2023 (last updated February 24, 2025)
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.
Attacker Value
Unknown

CVE-2022-4488

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4776

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4508

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4483

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4394

Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2022-3244

Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce
Attacker Value
Unknown

CVE-2022-3243

Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
Attacker Value
Unknown

CVE-2022-37611

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.
Attacker Value
Unknown

CVE-2022-36341

Disclosure Date: August 10, 2022 (last updated February 24, 2025)
Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS – Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress.