Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown

CVE-2023-25026

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in PayPal PayPal Brasil para WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Brasil para WooCommerce: from n/a through 1.4.2.
0
Attacker Value
Unknown

CVE-2023-27460

Disclosure Date: June 03, 2024 (last updated June 04, 2024)
Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34.
0
Attacker Value
Unknown

CVE-2023-23785

Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DgCult Exquisite PayPal Donation plugin <= v2.0.0 versions.
Attacker Value
Unknown

CVE-2023-0535

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-48345

Disclosure Date: February 24, 2023 (last updated October 08, 2023)
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
Attacker Value
Unknown

CVE-2022-21129

Disclosure Date: January 31, 2023 (last updated November 08, 2023)
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.
Attacker Value
Unknown

CVE-2021-23648

Disclosure Date: March 16, 2022 (last updated October 07, 2023)
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
Attacker Value
Unknown

CVE-2017-6217

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
0
Attacker Value
Unknown

CVE-2017-6215

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.
0
Attacker Value
Unknown

CVE-2017-6213

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.
0