Show filters
378 Total Results
Displaying 91-100 of 378
Sort by:
Attacker Value
Unknown

CVE-2023-43710

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1][MODULE_SHIPPING_PERCENT_TEXT_TITLE]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-43709

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1](MODULE)" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-43708

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1](MODULE_PAYMENT_SAGE_PAY_SERVER_TEXT_TITLE)" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-43707

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "CatalogsPageDescriptionForm[1][name] " parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-43706

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "email_templates_key" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-43705

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "translation_value[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-43704

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-43703

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "product_info[][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-43702

Disclosure Date: September 30, 2023 (last updated February 25, 2025)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tracking_number" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Attacker Value
Unknown

CVE-2023-3547

Disclosure Date: September 25, 2023 (last updated October 08, 2023)
The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks.