Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2024-11431

Disclosure Date: November 28, 2024 (last updated December 21, 2024)
The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-9985

Disclosure Date: October 15, 2024 (last updated October 17, 2024)
Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.
Attacker Value
Unknown

CVE-2024-9984

Disclosure Date: October 15, 2024 (last updated October 17, 2024)
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
Attacker Value
Unknown

CVE-2024-9983

Disclosure Date: October 15, 2024 (last updated October 17, 2024)
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
Attacker Value
Unknown

CVE-2023-41343

Disclosure Date: November 03, 2023 (last updated November 10, 2023)
Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.
Attacker Value
Unknown

CVE-2022-40739

Disclosure Date: October 31, 2022 (last updated February 24, 2025)
Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-Site Scripting) attack.