This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...
Continue ReadingJune 13, 2022
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers aut ...
Continue ReadingJune 13, 2022
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attac ...
Continue ReadingJune 13, 2022
The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site ScriptingRead More ...
Continue ReadingJune 13, 2022
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insuff ...
Continue ReadingJune 13, 2022
The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.Read More ...
Continue ReadingJune 13, 2022
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.Read More ...
Continue ReadingJune 13, 2022
The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.Read More ...
Continue ReadingJune 13, 2022
Back to Main