|
208451
|
4.8 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23702
|
2024-11-21 14:14 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208452
|
4.8 |
MEDIUM
Network
|
lavalite
|
lavalite
|
Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the Menu Links feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23700
|
2024-11-21 14:14 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208453
|
7.5 |
HIGH
Network
|
secondline
|
podcast_importer_secondline
|
Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24149
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208454
|
9.1 |
CRITICAL
Network
|
mooveagency
|
import_xml_and_rss_feeds
|
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24148
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208455
|
9.1 |
CRITICAL
Network
|
xylusthemes
|
wp_smart_import
|
Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24147
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208456
|
8.1 |
HIGH
Network
|
cminds
|
cm_download_manager
|
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fi…
|
CWE-22
Path Traversal
|
CVE-2020-24146
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208457
|
6.1 |
MEDIUM
Network
|
cminds
|
cm_download_manager
|
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted d…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24145
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208458
|
8.6 |
HIGH
Network
|
media_file_organizer_project
|
media_file_organizer
|
Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker get access to files that are stored outside the web root folder via the items[] …
|
CWE-22
Path Traversal
|
CVE-2020-24144
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208459
|
7.5 |
HIGH
Network
|
ninjateam
|
video_downloader_for_tiktok
|
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk…
|
CWE-22
Path Traversal
|
CVE-2020-24143
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208460
|
9.8 |
CRITICAL
Network
|
ninjateam
|
video_downloader_for_tiktok
|
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web app…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24142
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|