Lucene search

K

Tag Project Security Vulnerabilities

cve
cve

CVE-2023-23815

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Alan Jackson Multi-column Tag Map plugin <= 17.0.24...

6.5CVSS

5.2AI Score

0.001EPSS

2023-04-06 05:15 AM
16
cve
cve

CVE-2023-28995

Cross-Site Request Forgery (CSRF) vulnerability in Keith Solomon Configurable Tag Cloud (CTC) plugin <= 5.2...

8.8CVSS

8.8AI Score

0.001EPSS

2023-07-10 04:15 PM
6
cve
cve

CVE-2023-23875

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Himanshu Bing Site Verification plugin using Meta Tag plugin <= 1.0...

5.9CVSS

4.8AI Score

0.0005EPSS

2023-05-03 04:15 PM
17
cve
cve

CVE-2022-36417

Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in 3D Tag Cloud plugin <= 3.8 at...

6.1CVSS

6.1AI Score

0.001EPSS

2022-09-23 04:15 PM
27
4
cve
cve

CVE-2022-2412

The Better Tag Cloud WordPress plugin through 0.99.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite...

4.8CVSS

4.7AI Score

0.001EPSS

2022-08-08 02:15 PM
38
3
cve
cve

CVE-2022-2411

The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite...

4.8CVSS

4.7AI Score

0.001EPSS

2022-08-08 02:15 PM
38
4
cve
cve

CVE-2022-31560

The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used...

9.3CVSS

9.3AI Score

0.002EPSS

2022-07-11 01:15 AM
31
5
cve
cve

CVE-2020-29244

dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via...

6.5CVSS

6.4AI Score

0.001EPSS

2020-12-28 08:15 AM
30
2
cve
cve

CVE-2020-29243

dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via...

6.5CVSS

6.3AI Score

0.001EPSS

2020-12-28 08:15 AM
26
2
cve
cve

CVE-2020-29242

dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via...

6.5CVSS

6.3AI Score

0.001EPSS

2020-12-28 08:15 AM
32
2
cve
cve

CVE-2020-29245

dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via...

6.5CVSS

6.4AI Score

0.001EPSS

2020-12-28 08:15 AM
28
2
cve
cve

CVE-2020-15272

In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the tag input] or manage to alter the value of [the GITHUB_REF environment variable]. The problem has been patched in version...

9.6CVSS

9.6AI Score

0.001EPSS

2020-10-26 07:15 PM
16