Show filters
35 Total Results
Displaying 1-10 of 35
Sort by:
Attacker Value
Moderate
CVE-2020-11738
Disclosure Date: April 13, 2020 (last updated February 21, 2025)
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
1
Attacker Value
Unknown
CVE-2024-41961
Disclosure Date: August 01, 2024 (last updated August 02, 2024)
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which later flows into an `eval` sink which executes the code. Fixed in commit 8bce00be93b95a6512ff68fe86bf9554e486bc02.
0
Attacker Value
Unknown
CVE-2018-25095
Disclosure Date: January 08, 2024 (last updated January 12, 2024)
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
0
Attacker Value
Unknown
CVE-2023-3891
Disclosure Date: September 15, 2023 (last updated October 08, 2023)
Race condition in Lapce v0.2.8 allows an attacker to elevate privileges on the system
0
Attacker Value
Unknown
CVE-2023-38904
Disclosure Date: August 16, 2023 (last updated October 08, 2023)
A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted payload to the body parameter of the new post function.
0
Attacker Value
Unknown
CVE-2023-24398
Disclosure Date: April 07, 2023 (last updated November 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions.
0
Attacker Value
Unknown
CVE-2019-25095
Disclosure Date: January 05, 2023 (last updated October 20, 2023)
A vulnerability, which was classified as problematic, was found in kakwa LdapCherry up to 0.x. Affected is an unknown function of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.0 is able to address this issue. The patch is identified as 6f98076281e9452fdb1adcd1bcbb70a6f968ade9. It is recommended to upgrade the affected component. VDB-217434 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-2551
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.
0
Attacker Value
Unknown
CVE-2022-2552
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
0
Attacker Value
Unknown
CVE-2020-7526
Disclosure Date: August 31, 2020 (last updated February 22, 2025)
Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event.
0