Show filters
267 Total Results
Displaying 91-100 of 267
Sort by:
Attacker Value
Unknown

CVE-2023-40875

Disclosure Date: August 24, 2023 (last updated February 25, 2025)
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters.
Attacker Value
Unknown

CVE-2023-40874

Disclosure Date: August 24, 2023 (last updated February 25, 2025)
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters.
Attacker Value
Unknown

CVE-2023-38904

Disclosure Date: August 16, 2023 (last updated February 25, 2025)
A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted payload to the body parameter of the new post function.
Attacker Value
Unknown

CVE-2023-27416

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Decon Digital Decon WP SMS plugin <= 1.1 versions.
Attacker Value
Unknown

CVE-2023-36298

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).
Attacker Value
Unknown

CVE-2023-34842

Disclosure Date: July 31, 2023 (last updated February 25, 2025)
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
Attacker Value
Unknown

CVE-2023-38286

Disclosure Date: July 14, 2023 (last updated February 25, 2025)
Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.
Attacker Value
Unknown

CVE-2023-37839

Disclosure Date: July 13, 2023 (last updated February 25, 2025)
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Attacker Value
Unknown

CVE-2023-34090

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. Decidim uses a third-party library named Ransack for filtering certain database collections (e.g., public meetings). By default, this library allows filtering on all data attributes and associations. This allows an unauthenticated remote attacker to exfiltrate non-public data from the underlying database of a Decidim instance (e.g., exfiltrating data from the user table). This issue may lead to Sensitive Data Disclosure. The problem was patched in version 0.27.3.
Attacker Value
Unknown

CVE-2023-34089

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in version 0.27.3 and 0.26.7.