Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2025-23806

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFarmer Ultimate Subscribe allows Reflected XSS. This issue affects Ultimate Subscribe: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2024-1689

Disclosure Date: June 07, 2024 (last updated October 30, 2024)
The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woocommerce_tool_toggle_module() function in all versions up to, and including, 1.2.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to deactivate arbitrary plugin modules.
Attacker Value
Unknown

CVE-2008-5852

Disclosure Date: January 06, 2009 (last updated October 04, 2023)
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.
0
Attacker Value
Unknown

CVE-2005-2650

Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.
0