|
223101
|
6.1 |
MEDIUM
Network
|
frappe
|
frappe
|
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15700
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223102
|
4.3 |
MEDIUM
Network
|
octopus
|
octopus_server
|
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
|
NVD-CWE-noinfo
|
CVE-2019-15698
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223103
|
8.8 |
HIGH
Network
|
butlerblog
|
wp-members
|
The wp-members plugin before 3.2.8 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15660
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223104
|
4.3 |
MEDIUM
Network
|
easyupdatesmanager
|
easy_updates_manager
|
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
|
NVD-CWE-noinfo
|
CVE-2019-15650
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223105
|
9.8 |
CRITICAL
Network
|
genetechsolutions
|
pie_register
|
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
|
CWE-89
SQL Injection
|
CVE-2019-15659
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223106
|
8.8 |
HIGH
Network
|
elearningfreak
|
insert_or_embed_articulate_content
|
The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15649
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223107
|
6.5 |
MEDIUM
Network
|
elearningfreak
|
insert_or_embed_articulate_content
|
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
|
CWE-287 CWE-352 CWE-22 CWE-862
Improper Authentication Origin Validation Error Path Traversal Missing Authorization
|
CVE-2019-15648
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223108
|
8.8 |
HIGH
Network
|
groundhogg
|
groundhogg
|
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
|
CWE-94
Code Injection
|
CVE-2019-15647
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223109
|
9.8 |
CRITICAL
Network
|
carrcommunications
|
rsvpmaker
|
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-15646
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223110
|
8.8 |
HIGH
Network
|
zoho
|
salesiq
|
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15645
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|