CVE-2023-33314
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <=Â 1.1.3.1 versions.
Source: CVE-2023-33314
CVE-2023-33314
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <=Â 1.1.3.1 versions.
Source: CVE-2023-33314
CVE-2023-33309
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <=Â 4.5.11 versions.
Source: CVE-2023-33309
CVE-2023-33212
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.
Source: CVE-2023-33212
CVE-2023-32958
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <=Â 1.2.0 versions.
Source: CVE-2023-32958
CVE-2023-33328
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <=Â 4.0.9.1 versions.
Source: CVE-2023-33328
CVE-2023-33216
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9.
Source: CVE-2023-33216
CVE-2014-125101
A vulnerability classified as critical has been found in Portfolio Gallery Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. Upgrading to version 1.1.9 is able to address this issue. The name of the patch is 58ed88243e17df766036f4857041edaf358076d3. It is recommended to upgrade the affected component. The identifier VDB-230085 was assigned to this vulnerability.
Source: CVE-2014-125101
CVE-2015-10106
A vulnerability classified as critical was found in mback2k mh_httpbl Extension up to 1.1.7 on TYPO3. This vulnerability affects the function moduleContent of the file mod1/index.php. The manipulation leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.1.8 is able to address this issue. The name of the patch is 429f50f4e4795b20dae06735b41fb94f010722bf. It is recommended to upgrade the affected component. VDB-230086 is the identifier assigned to this vulnerability.
Source: CVE-2015-10106
CVE-2023-2951
A vulnerability classified as critical has been found in code-projects Bus Dispatch and Information System 1.0. Affected is an unknown function of the file delete_bus.php. The manipulation of the argument busid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230112.
Source: CVE-2023-2951
CVE-2023-2950
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
Source: CVE-2023-2950