Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2023-48841
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
0
Attacker Value
Unknown
CVE-2023-48840
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
0
Attacker Value
Unknown
CVE-2023-48839
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
0
Attacker Value
Unknown
CVE-2023-48838
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
0
Attacker Value
Unknown
CVE-2023-36127
Disclosure Date: October 10, 2023 (last updated October 14, 2023)
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
0
Attacker Value
Unknown
CVE-2023-36126
Disclosure Date: October 10, 2023 (last updated October 13, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0
0
Attacker Value
Unknown
CVE-2019-25094
Disclosure Date: January 04, 2023 (last updated October 20, 2023)
A vulnerability, which was classified as problematic, was found in innologi appointments Extension up to 2.0.5 on TYPO3. This affects an unknown part of the component Appointment Handler. The manipulation of the argument formfield leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.6 is able to address this issue. The identifier of the patch is 986d3cb34e5e086c6f04e061f600ffc5837abe7f. It is recommended to upgrade the affected component. The identifier VDB-217353 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-41660
Disclosure Date: January 24, 2022 (last updated October 07, 2023)
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
0
Attacker Value
Unknown
CVE-2020-35416
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.
0