Show filters
203 Total Results
Displaying 81-90 of 203
Sort by:
Attacker Value
Unknown
CVE-2023-5336
Disclosure Date: October 19, 2023 (last updated October 26, 2023)
The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2023-27615
Disclosure Date: October 06, 2023 (last updated October 11, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Dipak C. Gajjar WP Super Minify plugin <= 1.5.1 versions.
0
Attacker Value
Unknown
CVE-2023-41580
Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
0
Attacker Value
Unknown
CVE-2023-4965
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239732.
0
Attacker Value
Unknown
CVE-2023-39136
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.
0
Attacker Value
Unknown
CVE-2023-3954
Disclosure Date: August 21, 2023 (last updated October 08, 2023)
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-3366
Disclosure Date: August 21, 2023 (last updated October 08, 2023)
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack
0
Attacker Value
Unknown
CVE-2023-3671
Disclosure Date: August 07, 2023 (last updated October 08, 2023)
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-3365
Disclosure Date: August 07, 2023 (last updated October 08, 2023)
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment
0
Attacker Value
Unknown
CVE-2023-2843
Disclosure Date: August 07, 2023 (last updated October 08, 2023)
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.
0