Show filters
610 Total Results
Displaying 1-10 of 610
Sort by:
Attacker Value
Low

CVE-2019-11358

Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Attacker Value
High

CVE-2023-23752

Disclosure Date: February 16, 2023 (last updated October 08, 2023)
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Attacker Value
Unknown

CVE-2013-5576

Disclosure Date: October 09, 2013 (last updated October 05, 2023)
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.
1
Attacker Value
Unknown

CVE-2024-40749

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Access Controls allows access to protected views.
0
Attacker Value
Unknown

CVE-2024-40748

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Lack of output escaping in the id attribute of menu lists.
0
Attacker Value
Unknown

CVE-2024-40747

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Various module chromes didn't properly process inputs, leading to XSS vectors.
0
Attacker Value
Unknown

CVE-2024-9942

Disclosure Date: November 23, 2024 (last updated December 21, 2024)
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Attacker Value
Unknown

CVE-2024-9941

Disclosure Date: November 23, 2024 (last updated December 21, 2024)
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new user accounts with the administrator role.
Attacker Value
Unknown

CVE-2024-40743

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
0
Attacker Value
Unknown

CVE-2024-27187

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
Improper Access Controls allows backend users to overwrite their username when disallowed.
0