Show filters
610 Total Results
Displaying 1-10 of 610
Sort by:
Attacker Value
Low
CVE-2019-11358
Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
6
Attacker Value
High
CVE-2023-23752
Disclosure Date: February 16, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
1
Attacker Value
Unknown
CVE-2013-5576
Disclosure Date: October 09, 2013 (last updated October 05, 2023)
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.
1
Attacker Value
Unknown
CVE-2024-40749
Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Access Controls allows access to protected views.
0
Attacker Value
Unknown
CVE-2024-40748
Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Lack of output escaping in the id attribute of menu lists.
0
Attacker Value
Unknown
CVE-2024-40747
Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Various module chromes didn't properly process inputs, leading to XSS vectors.
0
Attacker Value
Unknown
CVE-2024-9942
Disclosure Date: November 23, 2024 (last updated December 21, 2024)
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2024-9941
Disclosure Date: November 23, 2024 (last updated December 21, 2024)
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new user accounts with the administrator role.
0
Attacker Value
Unknown
CVE-2024-40743
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
0
Attacker Value
Unknown
CVE-2024-27187
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
Improper Access Controls allows backend users to overwrite their username when disallowed.
0