Show filters
123 Total Results
Displaying 91-100 of 123
Sort by:
Attacker Value
Unknown

CVE-2022-40842

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
Attacker Value
Unknown

CVE-2022-40840

Disclosure Date: November 02, 2022 (last updated February 24, 2025)
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php.
Attacker Value
Unknown

CVE-2022-40839

Disclosure Date: November 01, 2022 (last updated February 24, 2025)
A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data.
Attacker Value
Unknown

CVE-2022-2594

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.
Attacker Value
Unknown

CVE-2022-2398

Disclosure Date: August 08, 2022 (last updated February 24, 2025)
The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2022-32567

Disclosure Date: July 07, 2022 (last updated February 24, 2025)
The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.
Attacker Value
Unknown

CVE-2022-23183

Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission.
Attacker Value
Unknown

CVE-2022-0474

Disclosure Date: February 07, 2022 (last updated February 23, 2025)
Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.
Attacker Value
Unknown

CVE-2021-24865

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
Attacker Value
Unknown

CVE-2021-20867

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.