Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2025-0509
Disclosure Date: February 04, 2025 (last updated February 17, 2025)
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
0
Attacker Value
Unknown
CVE-2024-53774
Disclosure Date: November 30, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sparkle WP Sparkle Elementor Kit allows DOM-Based XSS.This issue affects Sparkle Elementor Kit: from n/a through 2.0.9.
0
Attacker Value
Unknown
CVE-2024-6120
Disclosure Date: June 22, 2024 (last updated June 25, 2024)
The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all posts, pages, and uploaded files, as well as download and install a limited set of demo plugins.
0
Attacker Value
Unknown
CVE-2021-20084
Disclosure Date: April 23, 2021 (last updated November 28, 2024)
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.
0
Attacker Value
Unknown
CVE-2016-7838
Disclosure Date: June 09, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.
0
Attacker Value
Unknown
CVE-2006-3573
Disclosure Date: July 13, 2006 (last updated October 04, 2023)
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.
0
Attacker Value
Unknown
CVE-2005-3367
Disclosure Date: October 30, 2005 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field.
0