Show filters
321 Total Results
Displaying 81-90 of 321
Sort by:
Attacker Value
Unknown
CVE-2023-23749
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
0
Attacker Value
Unknown
CVE-2017-20167
Disclosure Date: January 14, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in Minichan. This affects an unknown part of the file reports.php. The manipulation of the argument headline leads to cross site scripting. It is possible to initiate the attack remotely. The identifier of the patch is fc0e732e58630cba318d6bf49d1388a7aa9d390e. It is recommended to apply a patch to fix this issue. The identifier VDB-217785 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2015-10025
Disclosure Date: January 07, 2023 (last updated February 24, 2025)
A vulnerability has been found in luelista miniConf up to 1.7.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file miniConf/MessageView.cs of the component URL Scanning. The manipulation leads to denial of service. Upgrading to version 1.7.7 and 1.8.0 is able to address this issue. The patch is named c06c2e5116c306e4e1bc79779f0eda2d1182f655. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217615.
0
Attacker Value
Unknown
CVE-2022-4200
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2022-45073
Disclosure Date: November 09, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
0
Attacker Value
Unknown
CVE-2022-42461
Disclosure Date: October 31, 2022 (last updated February 24, 2025)
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
0
Attacker Value
Unknown
CVE-2022-37620
Disclosure Date: October 31, 2022 (last updated February 24, 2025)
A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 via the candidate variable in htmlminifier.js.
0
Attacker Value
Unknown
CVE-2022-3517
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
0
Attacker Value
Unknown
CVE-2022-3082
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example
0
Attacker Value
Unknown
CVE-2022-33880
Disclosure Date: September 29, 2022 (last updated February 24, 2025)
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.
0