Show filters
217 Total Results
Displaying 1-10 of 217
Sort by:
Attacker Value
Unknown
CVE-2025-24710
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Gwolle Guestbook allows Reflected XSS. This issue affects Gwolle Guestbook: from n/a through 4.7.1.
0
Attacker Value
Unknown
CVE-2023-3476
Disclosure Date: June 30, 2023 (last updated October 08, 2023)
A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-232755.
0
Attacker Value
Unknown
CVE-2023-22985
Disclosure Date: April 06, 2023 (last updated October 08, 2023)
Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments.
0
Attacker Value
Unknown
CVE-2014-125053
Disclosure Date: January 06, 2023 (last updated October 20, 2023)
A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading to version 1.3.1 is able to address this issue. The patch is identified as 0cdd1c388edf15089c3a7541cefe7756e560581d. It is recommended to upgrade the affected component. VDB-217582 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-36830
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress.
0
Attacker Value
Unknown
CVE-2017-20089
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated remotely.
0
Attacker Value
Unknown
CVE-2021-24980
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page
0
Attacker Value
Unknown
CVE-2019-13949
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.
0
Attacker Value
Unknown
CVE-2019-13950
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.
0
Attacker Value
Unknown
CVE-2019-13948
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly block XSS payloads, as demonstrated by a crafted use of the onerror attribute of an IMG element.
0