|
196321
|
6.5 |
MEDIUM
Network
|
themeum
|
tutor_lms
|
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection th…
|
CWE-89
SQL Injection
|
CVE-2021-24186
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196322
|
5.4 |
MEDIUM
Network
|
elementor
|
website_builder
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24206
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196323
|
5.4 |
MEDIUM
Network
|
elementor
|
website_builder
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24205
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196324
|
5.4 |
MEDIUM
Network
|
elementor
|
website_builder
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24204
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196325
|
5.4 |
MEDIUM
Network
|
elementor
|
website_builder
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of po…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24203
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196326
|
5.4 |
MEDIUM
Network
|
elementor
|
website_builder
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24202
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196327
|
5.4 |
MEDIUM
Network
|
elementor
|
website_builder
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of po…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24201
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196328
|
6.5 |
MEDIUM
Network
|
themeum
|
tutor_lms
|
The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploite…
|
CWE-89
SQL Injection
|
CVE-2021-24185
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196329
|
8.8 |
HIGH
Network
|
themeum
|
tutor_lms
|
Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privile…
|
-
|
CVE-2021-24184
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196330
|
6.5 |
MEDIUM
Network
|
themeum
|
tutor_lms
|
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be …
|
CWE-89
SQL Injection
|
CVE-2021-24183
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|