Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2023-36502

Disclosure Date: July 25, 2023 (last updated October 08, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <= 1.3.2 versions.
Attacker Value
Unknown

CVE-2023-29430

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions.
Attacker Value
Unknown

CVE-2023-29236

Disclosure Date: April 07, 2023 (last updated November 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions.
Attacker Value
Unknown

CVE-2023-25041

Disclosure Date: April 07, 2023 (last updated November 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions.
Attacker Value
Unknown

CVE-2019-20210

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
Attacker Value
Unknown

CVE-2019-20212

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
Attacker Value
Unknown

CVE-2019-20211

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.
Attacker Value
Unknown

CVE-2019-20209

Disclosure Date: June 19, 2019 (last updated February 21, 2025)
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.