Show filters
140 Total Results
Displaying 91-100 of 140
Sort by:
Attacker Value
Unknown

CVE-2021-24603

Disclosure Date: September 06, 2021 (last updated February 23, 2025)
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2021-24492

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.
Attacker Value
Unknown

CVE-2021-24296

Disclosure Date: May 24, 2021 (last updated February 22, 2025)
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled
Attacker Value
Unknown

CVE-2021-24135

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.
Attacker Value
Unknown

CVE-2020-2269

Disclosure Date: September 16, 2020 (last updated February 22, 2025)
Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to configure views.
Attacker Value
Unknown

CVE-2019-19826

Disclosure Date: December 16, 2019 (last updated November 27, 2024)
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.
Attacker Value
Unknown

CVE-2011-3373

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack.
Attacker Value
Unknown

CVE-2019-16251

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
Attacker Value
Unknown

CVE-2015-9526

Disclosure Date: October 23, 2019 (last updated February 08, 2025)
The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Attacker Value
Unknown

CVE-2019-15560

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
0