Lucene search

K

Widgets Security Vulnerabilities

cve
cve

CVE-2020-9382

An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser...

5.4CVSS

6.3AI Score

0.001EPSS

2020-02-24 11:15 PM
43
cve
cve

CVE-2015-9438

The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance...

5.4CVSS

5.3AI Score

0.001EPSS

2019-09-26 02:15 AM
121
cve
cve

CVE-2015-9437

The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit...

6.5CVSS

6.2AI Score

0.002EPSS

2019-09-26 02:15 AM
114
cve
cve

CVE-2015-9436

The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id...

5.4CVSS

5.3AI Score

0.001EPSS

2019-09-26 02:15 AM
118
cve
cve

CVE-2015-6737

Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded...

5.5AI Score

0.003EPSS

2015-09-01 02:59 PM
21
cve
cve

CVE-2014-6010

The Rasta Weed Widgets HD (aka aw.awesomewidgets.rastaweed) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-22 10:55 AM
19
cve
cve

CVE-2013-1973

The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissions, which allows remote authenticated users to obtain sensitive field values via unspecified...

6.2AI Score

0.002EPSS

2014-06-09 07:55 PM
19
cve
cve

CVE-2007-4034

Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. ...

7.8AI Score

0.913EPSS

2007-07-27 10:30 PM
29
Total number of security vulnerabilities158