Lucene search

K

Instagram Security Vulnerabilities

cve
cve

CVE-2023-43982

Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at insta_parser.php. This vulnerability allows attackers to use the vulnerable website as proxy to attack other websites or exfiltrate data via a HTTP...

9.8CVSS

9.3AI Score

0.001EPSS

2023-11-03 05:15 AM
12
cve
cve

CVE-2023-5357

The Instagram for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with...

6.4CVSS

5.3AI Score

0.0004EPSS

2023-10-04 02:15 AM
59
cve
cve

CVE-2023-29748

Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the...

7.5CVSS

7.2AI Score

0.001EPSS

2023-06-01 03:15 AM
76
cve
cve

CVE-2023-29747

Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the...

9.8CVSS

9AI Score

0.002EPSS

2023-05-31 04:15 PM
12
cve
cve

CVE-2017-20087

A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched...

6.1CVSS

5.9AI Score

0.001EPSS

2022-06-23 05:15 AM
19
8
cve
cve

CVE-2020-20094

Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted...

6.5CVSS

6AI Score

0.002EPSS

2022-03-23 10:15 PM
45
cve
cve

CVE-2020-1895

A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dimensions. This affects versions prior to...

7.8CVSS

7.6AI Score

0.001EPSS

2020-04-09 05:15 PM
117
cve
cve

CVE-2015-9432

The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab...

6.5CVSS

6.2AI Score

0.002EPSS

2019-09-26 02:15 AM
122
cve
cve

CVE-2019-14470

cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description...

6.1CVSS

5.8AI Score

0.751EPSS

2019-09-04 08:15 PM
146
cve
cve

CVE-2018-13849

edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on...

6.1CVSS

5.9AI Score

0.001EPSS

2018-07-10 06:29 PM
42
cve
cve

CVE-2018-10300

Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's...

6.1CVSS

6.1AI Score

0.001EPSS

2018-04-23 06:29 PM
26
cve
cve

CVE-2018-10301

Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram...

6.1CVSS

6.3AI Score

0.001EPSS

2018-04-23 06:29 PM
31
cve
cve

CVE-2017-17869

The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media...

6.1CVSS

6AI Score

0.001EPSS

2017-12-27 05:08 PM
24
cve
cve

CVE-2017-16758

Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "access_token"...

4.8CVSS

5.1AI Score

0.001EPSS

2017-11-09 10:29 PM
26
cve
cve

CVE-2014-6834

The Instaroid - Instagram Viewer (aka net.muik.instaroid) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-30 10:55 AM
20
cve
cve

CVE-2014-6690

The InstaMessage - Instagram Chat (aka com.futurebits.instamessage.free) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-23 10:55 AM
23
cve
cve

CVE-2014-6007

The LikeHero Get Instagram Likes (aka com.fraoula.likehero) application 1.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-22 10:55 AM
20
cve
cve

CVE-2014-5679

The PopU 2: Get Likes on Instagram (aka com.popuapp.popu) application 1.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 01:55 AM
14
cve
cve

CVE-2014-5675

The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 01:55 AM
22
cve
cve

CVE-2014-5643

The Instachat -Instagram Messenger (aka com.instachat.android) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 01:55 AM
19
cve
cve

CVE-2014-5622

The Follow Mania for Instagram (aka com.followmania) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 01:55 AM
20
cve
cve

CVE-2014-5585

The Like4Like: Get Instagram Likes (aka com.bepop.bepop) application 2.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 01:55 AM
18