Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2023-33208
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gsmith Cookie Monster plugin <= 1.51 versions.
0
Attacker Value
Unknown
CVE-2022-3811
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2022-23395
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).
0
Attacker Value
Unknown
CVE-2021-24653
Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-24595
Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.
0
Attacker Value
Unknown
CVE-2016-1000236
Disclosure Date: November 19, 2019 (last updated November 08, 2023)
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
0
Attacker Value
Unknown
CVE-2019-16522
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. An attacker with high privileges can attack other users.
0
Attacker Value
Unknown
CVE-2017-18589
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.
0
Attacker Value
Unknown
CVE-2018-10309
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
0
Attacker Value
Unknown
CVE-2012-5856
Disclosure Date: November 17, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka uk-cookie) plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0