Show filters
286 Total Results
Displaying 81-90 of 286
Sort by:
Attacker Value
Unknown

CVE-2023-24269

Disclosure Date: April 28, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.
Attacker Value
Unknown

CVE-2023-0388

Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers.
Attacker Value
Unknown

CVE-2023-26852

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file.
Attacker Value
Unknown

CVE-2023-1004

Disclosure Date: February 24, 2023 (last updated October 20, 2023)
A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component WSH JScript Handler. The manipulation leads to code injection. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-221737 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-32854

Disclosure Date: February 21, 2023 (last updated October 08, 2023)
textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches.
Attacker Value
Unknown

CVE-2023-0252

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2023-0070

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-4548

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.
Attacker Value
Unknown

CVE-2022-45927

Disclosure Date: January 18, 2023 (last updated October 08, 2023)
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication of the QDS endpoints of the Content Server. These endpoints can be used to create objects and execute arbitrary code.
Attacker Value
Unknown

CVE-2022-45923

Disclosure Date: January 18, 2023 (last updated October 08, 2023)
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker to increase/decrease an arbitrary memory address by 1 and trigger a call to a method of a vftable with a vftable pointer value chosen by the attacker.