Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

github логотип

GHSA-3xgr-6gm3-9657

около 4 лет назад

Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3p9r-g8j3-8wq4

около 4 лет назад

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

EPSS: Низкий
github логотип

GHSA-3hwg-mg48-rrmm

около 4 лет назад

SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3hg9-j6q2-m4g8

около 4 лет назад

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

EPSS: Средний
github логотип

GHSA-3g3m-8hg3-56fh

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

EPSS: Низкий
github логотип

GHSA-3cqg-3c94-rm6p

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter.

EPSS: Низкий
github логотип

GHSA-39gp-f464-jp5h

около 4 лет назад

Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

EPSS: Низкий
github логотип

GHSA-37rh-3g8c-j28w

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

EPSS: Низкий
github логотип

GHSA-372h-g394-rq35

около 4 лет назад

Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.

EPSS: Низкий
github логотип

GHSA-2xvq-8gjc-grfh

около 4 лет назад

SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

EPSS: Низкий
github логотип

GHSA-2xjj-2wcr-mj9m

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-admin.php.

EPSS: Низкий
github логотип

GHSA-2xfx-56hw-759c

около 4 лет назад

Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.

EPSS: Низкий
github логотип

GHSA-2w3m-vv2j-4cpr

около 4 лет назад

SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php.

EPSS: Низкий
github логотип

GHSA-2vq6-7g93-mrhp

около 4 лет назад

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-2p5h-p2qg-hvcq

около 4 лет назад

SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-2hhx-g28r-fqwv

около 4 лет назад

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.

EPSS: Низкий
github логотип

GHSA-2gwv-7wq2-wv5g

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2gph-8pg4-626q

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

EPSS: Низкий
github логотип

GHSA-2cv7-399j-p9vv

около 4 лет назад

SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-277w-qpxr-2549

около 4 лет назад

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3xgr-6gm3-9657

Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. NOTE: some of these details are obtained from third party information.

4%
Низкий
около 4 лет назад
github логотип
GHSA-3p9r-g8j3-8wq4

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

6%
Низкий
около 4 лет назад
github логотип
GHSA-3hwg-mg48-rrmm

SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-3hg9-j6q2-m4g8

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

11%
Средний
около 4 лет назад
github логотип
GHSA-3g3m-8hg3-56fh

Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3cqg-3c94-rm6p

Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-39gp-f464-jp5h

Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-37rh-3g8c-j28w

Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-372h-g394-rq35

Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.

9%
Низкий
около 4 лет назад
github логотип
GHSA-2xvq-8gjc-grfh

SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2xjj-2wcr-mj9m

Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-admin.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2xfx-56hw-759c

Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2w3m-vv2j-4cpr

SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php.

7%
Низкий
около 4 лет назад
github логотип
GHSA-2vq6-7g93-mrhp

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2p5h-p2qg-hvcq

SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2hhx-g28r-fqwv

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2gwv-7wq2-wv5g

Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors. NOTE: some of these details are obtained from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2gph-8pg4-626q

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

2%
Низкий
около 4 лет назад
github логотип
GHSA-2cv7-399j-p9vv

SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are obtained from third party information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-277w-qpxr-2549

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
6%
Низкий
около 4 лет назад

Уязвимостей на страницу