Lucene search

K

Website Security Vulnerabilities

cve
cve

CVE-2023-0329

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator...

7.2CVSS

7.1AI Score

0.001EPSS

2023-05-30 08:15 AM
898
cve
cve

CVE-2023-2397

A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_field. The manipulation of the argument Field Name leads to cross site scripting. The attack....

4.8CVSS

4.9AI Score

0.001EPSS

2023-04-28 10:15 PM
19
cve
cve

CVE-2023-2038

A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin_class.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been...

7.5CVSS

7.9AI Score

0.002EPSS

2023-04-14 08:15 AM
64
cve
cve

CVE-2023-2037

A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been classified as critical. This affects an unknown part of the file watch.php. The manipulation of the argument code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to.....

9.8CVSS

9.7AI Score

0.002EPSS

2023-04-14 08:15 AM
67
cve
cve

CVE-2023-2036

A vulnerability was found in Campcodes Video Sharing Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file upload.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed.....

7.5CVSS

7.8AI Score

0.002EPSS

2023-04-14 07:15 AM
16
2
cve
cve

CVE-2023-2035

A vulnerability has been found in Campcodes Video Sharing Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file signup.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been....

7.5CVSS

7.8AI Score

0.002EPSS

2023-04-14 07:15 AM
63
cve
cve

CVE-2023-1908

A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/categories/view_category.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection......

9.8CVSS

9.7AI Score

0.001EPSS

2023-04-06 01:15 PM
14
cve
cve

CVE-2023-1792

A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/fields/manage_field.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql...

9.8CVSS

9.6AI Score

0.001EPSS

2023-04-02 07:15 AM
24
cve
cve

CVE-2023-1418

A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file cashconfirm.php of the component POST Parameter Handler. The manipulation of the argument...

6.1CVSS

6AI Score

0.001EPSS

2023-03-15 04:15 PM
26
cve
cve

CVE-2023-1379

A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file addmem.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to sql...

9.8CVSS

9.7AI Score

0.001EPSS

2023-03-15 04:15 PM
26
cve
cve

CVE-2023-1378

A vulnerability classified as critical was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. This vulnerability affects unknown code of the file paypalsuccess.php of the component POST Parameter Handler. The manipulation of the argument cusid leads to sql injection....

9.8CVSS

9.7AI Score

0.001EPSS

2023-03-13 06:15 PM
22
cve
cve

CVE-2023-0172

The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting...

5.4CVSS

5.3AI Score

0.001EPSS

2023-03-13 05:15 PM
32
cve
cve

CVE-2023-1311

A vulnerability, which was classified as critical, was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. This affects an unknown part of the file large.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is...

9.8CVSS

9.7AI Score

0.001EPSS

2023-03-10 08:15 AM
56
cve
cve

CVE-2023-1301

A vulnerability, which was classified as critical, has been found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this issue is some unknown functionality of the file deleteorder.php of the component GET Parameter Handler. The manipulation of the argument id...

9.8CVSS

9.6AI Score

0.001EPSS

2023-03-09 10:15 PM
56
cve
cve

CVE-2023-1041

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Responsive Tourism Website 1.0. This affects an unknown part of the file /tourism/rate_review.php. The manipulation of the argument id with the input 1">alert(1111) leads to cross site scripting. It is...

6.1CVSS

6AI Score

0.001EPSS

2023-02-26 12:15 PM
50
cve
cve

CVE-2022-45527

File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg...

9.8CVSS

9.2AI Score

0.002EPSS

2023-02-08 07:15 PM
14
cve
cve

CVE-2022-45526

SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to...

9.8CVSS

9.9AI Score

0.001EPSS

2023-02-08 07:15 PM
18
cve
cve

CVE-2017-20150

A vulnerability was found in challenge website. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The name of the patch is f1644b1d3502e5aa5284f31ea80d2623817f4d42. It is recommended to apply a patch to fix this issue. The...

8.8CVSS

9AI Score

0.002EPSS

2022-12-28 07:15 PM
24
cve
cve

CVE-2022-45990

A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail...

6.1CVSS

5.8AI Score

0.001EPSS

2022-12-05 11:15 PM
26
cve
cve

CVE-2009-4688

Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid...

6AI Score

0.002EPSS

2022-10-03 04:24 PM
20
cve
cve

CVE-2009-4689

SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid...

8.8AI Score

0.002EPSS

2022-10-03 04:24 PM
21
cve
cve

CVE-2009-3162

Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default...

5.9AI Score

0.001EPSS

2022-10-03 04:23 PM
23
cve
cve

CVE-2002-2413

WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file...

7.2AI Score

0.002EPSS

2022-10-03 04:23 PM
21
cve
cve

CVE-2005-2135

SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2...

8.8AI Score

0.001EPSS

2022-10-03 04:22 PM
25
cve
cve

CVE-2018-20612

UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do...

8.8CVSS

8.6AI Score

0.001EPSS

2022-10-03 04:22 PM
20
cve
cve

CVE-2011-3817

Website Baker 2.8.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/media/parameters.php and certain other files. NOTE: this might overlap...

6.3AI Score

0.01EPSS

2022-10-03 04:15 PM
28
cve
cve

CVE-2021-41433

SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through...

9.8CVSS

10AI Score

0.002EPSS

2022-09-27 11:15 PM
22
3
cve
cve

CVE-2022-40087

Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP...

9.8CVSS

9.6AI Score

0.005EPSS

2022-09-22 10:15 PM
32
7
cve
cve

CVE-2022-40089

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to...

9.8CVSS

9.5AI Score

0.023EPSS

2022-09-22 10:15 PM
24
6
cve
cve

CVE-2022-40088

Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page...

6.1CVSS

6AI Score

0.001EPSS

2022-09-22 10:15 PM
22
5
cve
cve

CVE-2022-2515

The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pro_version_activation_code parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, including those....

6.4CVSS

5AI Score

0.001EPSS

2022-09-06 06:15 PM
32
3
cve
cve

CVE-2022-2516

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to....

6.4CVSS

5AI Score

0.001EPSS

2022-09-06 06:15 PM
23
3
cve
cve

CVE-2022-2430

The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to...

6.4CVSS

5AI Score

0.001EPSS

2022-09-06 06:15 PM
29
5
cve
cve

CVE-2022-36572

Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component...

9.8CVSS

9.8AI Score

0.006EPSS

2022-08-29 12:15 AM
32
8
cve
cve

CVE-2022-2769

A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue affects some unknown processing of the file /dashboard/contact. The manipulation of the argument phone leads to cross site scripting. The attack may be initiated remotely. The...

5.4CVSS

5.2AI Score

0.001EPSS

2022-08-11 12:15 PM
21
2
cve
cve

CVE-2022-2765

A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has....

9.8CVSS

9.5AI Score

0.008EPSS

2022-08-11 10:15 AM
28
3
cve
cve

CVE-2022-2751

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The...

9.8CVSS

9.3AI Score

0.002EPSS

2022-08-11 05:15 AM
27
3
cve
cve

CVE-2022-2750

A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack...

9.8CVSS

9.4AI Score

0.002EPSS

2022-08-11 05:15 AM
19
3
cve
cve

CVE-2022-2740

A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated....

9.8CVSS

9.5AI Score

0.002EPSS

2022-08-11 05:15 AM
26
4
cve
cve

CVE-2022-2736

A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is...

9.8CVSS

9.4AI Score

0.002EPSS

2022-08-11 05:15 AM
30
5
cve
cve

CVE-2022-2725

A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier...

6.1CVSS

6AI Score

0.001EPSS

2022-08-09 07:15 AM
22
7
cve
cve

CVE-2022-35493

A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search...

6.1CVSS

6AI Score

0.001EPSS

2022-08-08 03:15 PM
36
4
cve
cve

CVE-2022-2269

The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL...

9.8CVSS

9.7AI Score

0.002EPSS

2022-08-08 02:15 PM
37
3
cve
cve

CVE-2022-2702

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be launched remotely....

7.3CVSS

6.5AI Score

0.001EPSS

2022-08-08 01:15 PM
31
5
cve
cve

CVE-2022-2694

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier.....

8.8CVSS

8.7AI Score

0.001EPSS

2022-08-06 06:15 PM
26
9
cve
cve

CVE-2022-29455

DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5...

6.1CVSS

5.8AI Score

0.002EPSS

2022-06-13 05:15 PM
93
5
cve
cve

CVE-2022-30015

In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored...

5.4CVSS

5.3AI Score

0.001EPSS

2022-05-23 09:16 PM
46
4
cve
cve

CVE-2022-30014

Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater...

8.8CVSS

8.8AI Score

0.002EPSS

2022-05-23 04:16 PM
38
4
cve
cve

CVE-2022-27330

A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text...

5.4CVSS

5.2AI Score

0.001EPSS

2022-05-03 08:15 PM
44
cve
cve

CVE-2022-24864

Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to /presale/join. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is delivered to the...

5.4CVSS

5.6AI Score

0.001EPSS

2022-04-20 07:15 PM
50
Total number of security vulnerabilities272