All CVEs — page 164 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows unauthenticated users to perform SQL injection attacks due to insufficient parameter sanitization in the VikRentItems plugin before 1.2.4, potentially leading to data compromise.
The flaw allows unauthenticated users to update settings in the Master Blocks WordPress plugin, leading to Stored XSS that can be executed in the session of any administrator visiting a wp-admin page.
This flaw allows unauthenticated users to update WordPress options and store executable scripts, leading to potential full site takeover and privilege escalation.
The flaw allows unauthenticated attackers to inject JavaScript into the page title, potentially leading to cross-site scripting (XSS) attacks.