Show filters
267 Total Results
Displaying 81-90 of 267
Sort by:
Attacker Value
Unknown

CVE-2023-48068

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.
Attacker Value
Unknown

CVE-2023-36465

Disclosure Date: October 06, 2023 (last updated October 12, 2023)
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.
Attacker Value
Unknown

CVE-2023-5301

Disclosure Date: September 30, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240940.
Attacker Value
Unknown

CVE-2023-43226

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
Attacker Value
Unknown

CVE-2023-5022

Disclosure Date: September 17, 2023 (last updated February 25, 2025)
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.
Attacker Value
Unknown

CVE-2023-40784

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
Attacker Value
Unknown

CVE-2023-4747

Disclosure Date: September 04, 2023 (last updated February 25, 2025)
A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manipulation of the argument tag_alias leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238636.
Attacker Value
Unknown

CVE-2023-41049

Disclosure Date: September 01, 2023 (last updated February 25, 2025)
@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.
Attacker Value
Unknown

CVE-2023-40877

Disclosure Date: August 24, 2023 (last updated February 25, 2025)
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.
Attacker Value
Unknown

CVE-2023-40876

Disclosure Date: August 24, 2023 (last updated February 25, 2025)
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.