Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Unknown
CVE-2024-38723
Disclosure Date: July 22, 2024 (last updated August 15, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6.
0
Attacker Value
Unknown
CVE-2022-48623
Disclosure Date: February 13, 2024 (last updated October 31, 2024)
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
0
Attacker Value
Unknown
CVE-2023-6268
Disclosure Date: December 26, 2023 (last updated January 04, 2024)
The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-50472
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
0
Attacker Value
Unknown
CVE-2023-50471
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
0
Attacker Value
Unknown
CVE-2021-32292
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
0
Attacker Value
Unknown
CVE-2022-47937
Disclosure Date: May 15, 2023 (last updated March 29, 2024)
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input.
The org.apache.sling.commons.json bundle has been deprecated as of March
2017 and should not be used anymore. Consumers are encouraged to
consider the Apache Sling Commons Johnzon OSGi bundle provided by the
Apache Sling project, but may of course use other JSON libraries.
0
Attacker Value
Unknown
CVE-2023-25485
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions.
0
Attacker Value
Unknown
CVE-2022-41714
Disclosure Date: November 03, 2022 (last updated December 22, 2024)
fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.
0
Attacker Value
Unknown
CVE-2022-25845
Disclosure Date: June 10, 2022 (last updated October 07, 2023)
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
0