Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2019-15317: WordPress Plugin Give - Stored XSS for Donors

The give plugin before 2.4.7 for WordPress has XSS via a donor name.

CVE
#xss#vulnerability#web#wordpress#php
CVE-2019-14246: CentOS-WebPanel.com Control Web Panel (CWP) 0.9.8.851 phpMyAdmin Password Change ≈ Packet Storm

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.

CVE-2019-13477: CentOS-Control-Web-Panel-CVE/CVE-2019-13477.md at master · i3umi3iei3ii/CentOS-Control-Web-Panel-CVE

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.

CVE-2019-5041: TALOS-2019-0805 || Cisco Talos Intelligence Group

An exploitable Stack Based Buffer Overflow vulnerability exists in the EnumMetaInfo function of Aspose Aspose.Words library, version 18.11.0.0. A specially crafted doc file can cause a stack-based buffer overflow, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger this vulnerability.

CVE-2017-18539: WebLibrarian

The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.

CVE-2015-9320: OptionTree

The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.

CVE-2016-10893: Crayon Syntax Highlighter

The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.

CVE-2019-14789

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.