Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-11198

Disclosure Date: November 19, 2024 (last updated November 20, 2024)
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-38709

Disclosure Date: July 12, 2024 (last updated July 13, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating System allows PHP Local File Inclusion.This issue affects GD Rating System: from n/a through 3.6.
0
Attacker Value
Unknown

CVE-2024-25093

Disclosure Date: February 29, 2024 (last updated January 17, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Rating System: from n/a through 3.5.
Attacker Value
Unknown

CVE-2017-18591

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
0
Attacker Value
Unknown

CVE-2018-5292

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
0
Attacker Value
Unknown

CVE-2018-5293

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
0
Attacker Value
Unknown

CVE-2018-5289

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
0
Attacker Value
Unknown

CVE-2018-5288

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
0
Attacker Value
Unknown

CVE-2018-5287

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
0
Attacker Value
Unknown

CVE-2018-5290

Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
0