Show filters
104 Total Results
Displaying 81-90 of 104
Sort by:
Attacker Value
Unknown
CVE-2020-36550
Disclosure Date: July 15, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php.
0
Attacker Value
Unknown
CVE-2020-35261
Disclosure Date: July 15, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.
0
Attacker Value
Unknown
CVE-2022-1952
Disclosure Date: July 11, 2022 (last updated October 07, 2023)
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.
0
Attacker Value
Unknown
CVE-2022-29923
Disclosure Date: May 12, 2022 (last updated September 17, 2024)
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1.
0
Attacker Value
Unknown
CVE-2021-24965
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins
0
Attacker Value
Unknown
CVE-2021-44091
Disclosure Date: January 20, 2022 (last updated February 23, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.
0
Attacker Value
Unknown
CVE-2021-24722
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-24299
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to make a restaurant reservation field called 'Comment' does not use proper input validation and can be used to store XSS payloads. The XSS payloads will be executed when the plugin user goes to the 'Upcoming' page, which is an external website https://upcoming.reservationdiary.eu/ loaded in an iframe, and the stored reservation with XSS payload is loaded.
0
Attacker Value
Unknown
CVE-2020-29045
Disclosure Date: March 11, 2021 (last updated February 22, 2025)
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
0
Attacker Value
Unknown
CVE-2020-26773
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.
0