Show filters
123 Total Results
Displaying 91-100 of 123
Sort by:
Attacker Value
Unknown
CVE-2022-40842
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
0
Attacker Value
Unknown
CVE-2022-40840
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php.
0
Attacker Value
Unknown
CVE-2022-40839
Disclosure Date: November 01, 2022 (last updated February 24, 2025)
A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data.
0
Attacker Value
Unknown
CVE-2022-2594
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.
0
Attacker Value
Unknown
CVE-2022-2398
Disclosure Date: August 08, 2022 (last updated February 24, 2025)
The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2022-32567
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.
0
Attacker Value
Unknown
CVE-2022-23183
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission.
0
Attacker Value
Unknown
CVE-2022-0474
Disclosure Date: February 07, 2022 (last updated February 23, 2025)
Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the notification is set to be sent to each recipient individually. This issue affects: OTRS AG OTRSCustomContactFields 8.0.x version: 8.0.11 and prior versions.
0
Attacker Value
Unknown
CVE-2021-24865
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
0
Attacker Value
Unknown
CVE-2021-20867
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.
0