Show filters
53 Total Results
Displaying 1-10 of 53
Sort by:
Attacker Value
Unknown

CVE-2025-23892

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Furr and Simon Ward Progress Tracker allows DOM-Based XSS.This issue affects Progress Tracker: from n/a through 0.9.3.
0
Attacker Value
Unknown

CVE-2025-22515

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simon Chuang Show Google Analytics widget allows Stored XSS.This issue affects Show Google Analytics widget: from n/a through 1.5.4.
0
Attacker Value
Unknown

CVE-2025-22358

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcon Simone Wp advertising management allows Reflected XSS.This issue affects Wp advertising management: from n/a through 1.0.3.
0
Attacker Value
Unknown

CVE-2024-1093

Disclosure Date: March 05, 2024 (last updated January 12, 2025)
The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_logic() function hooked via admin_init in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to update the memory limit.
Attacker Value
Unknown

CVE-2022-2413

Disclosure Date: January 16, 2024 (last updated January 25, 2024)
The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even when the unfiltered_html capability is disabled.
Attacker Value
Unknown

CVE-2023-28499

Disclosure Date: November 07, 2023 (last updated November 16, 2023)
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions.
Attacker Value
Unknown

CVE-2023-30497

Disclosure Date: September 06, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Simon Chuang WP LINE Notify plugin <= 1.4.4 versions.
Attacker Value
Unknown

CVE-2023-36307

Disclosure Date: September 05, 2023 (last updated November 08, 2023)
ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
Attacker Value
Unknown

CVE-2023-38695

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.
Attacker Value
Unknown

CVE-2015-9401

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS.