Show filters
43 Total Results
Displaying 1-10 of 43
Sort by:
Attacker Value
Unknown
CVE-2025-22703
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6.
0
Attacker Value
Unknown
CVE-2025-23569
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Kelvin Ng Shortcode in Comment allows Stored XSS.This issue affects Shortcode in Comment: from n/a through 1.1.1.
0
Attacker Value
Unknown
CVE-2024-11430
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' shortcode in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2024-9456
Disclosure Date: October 26, 2024 (last updated January 06, 2025)
The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0
Attacker Value
Unknown
CVE-2024-49399
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information.
0
Attacker Value
Unknown
CVE-2024-49398
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.
0
Attacker Value
Unknown
CVE-2024-49397
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication and takeover admin accounts.
0
Attacker Value
Unknown
CVE-2024-49396
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.
0
Attacker Value
Unknown
CVE-2024-45813
Disclosure Date: September 18, 2024 (last updated September 19, 2024)
find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, like `/:a-:b-`. This may cause a denial of service in some instances. Users are advised to update to find-my-way v8.2.2 or v9.0.1. or subsequent versions. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2023-52198
Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125.
0