Lucene search

K

Websoft Security Vulnerabilities

cve
cve

CVE-2024-2960

The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the deletePricingTable() function. This makes it possible for unauthenticated attackers to delete pricing...

4.3CVSS

6.3AI Score

0.0005EPSS

2024-05-02 05:15 PM
23
cve
cve

CVE-2024-2959

The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the savePricingTable() function. This makes it possible for unauthenticated attackers to create and edit...

4.3CVSS

6.3AI Score

0.0005EPSS

2024-05-02 05:15 PM
25
cve
cve

CVE-2024-2958

The SVS Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pricing table settings in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

4.4CVSS

7.7AI Score

0.0004EPSS

2024-05-02 05:15 PM
23
cve
cve

CVE-2022-46905

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected...

6.1CVSS

6.2AI Score

0.001EPSS

2022-12-12 09:15 PM
28
cve
cve

CVE-2022-46903

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Stored...

5.4CVSS

5.3AI Score

0.001EPSS

2022-12-12 09:15 PM
31
cve
cve

CVE-2022-46904

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to...

5.4CVSS

5.3AI Score

0.001EPSS

2022-12-12 09:15 PM
26
cve
cve

CVE-2022-46906

Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected...

5.4CVSS

5.4AI Score

0.001EPSS

2022-12-12 09:15 PM
24
cve
cve

CVE-2007-1720

Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log...

7.2AI Score

0.047EPSS

2007-03-28 12:19 AM
23
cve
cve

CVE-2004-0625

SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login...

8.5AI Score

0.002EPSS

2004-12-06 05:00 AM
24