unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2022-4648
The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:59 +0000 UTC Push: 2023-01-17 01:59:01 +0000 UTC |
Live-Hack-CVE/CVE-2022-4578
The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:54 +0000 UTC Push: 2023-01-17 01:58:57 +0000 UTC |
Live-Hack-CVE/CVE-2022-4571
The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:50 +0000 UTC Push: 2023-01-17 01:58:53 +0000 UTC |
Live-Hack-CVE/CVE-2022-4549
The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:46 +0000 UTC Push: 2023-01-17 01:58:49 +0000 UTC |
Live-Hack-CVE/CVE-2022-4547
The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by [high privilege users such as admin|users with a role as low as admin. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:41 +0000 UTC Push: 2023-01-17 01:58:44 +0000 UTC |
Live-Hack-CVE/CVE-2022-4544
The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:38 +0000 UTC Push: 2023-01-17 01:58:40 +0000 UTC |
Live-Hack-CVE/CVE-2022-4508
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:33 +0000 UTC Push: 2023-01-17 01:58:36 +0000 UTC |
Live-Hack-CVE/CVE-2022-4507
The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:29 +0000 UTC Push: 2023-01-17 01:58:32 +0000 UTC |
Live-Hack-CVE/CVE-2022-4487
The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:25 +0000 UTC Push: 2023-01-17 01:58:27 +0000 UTC |
Live-Hack-CVE/CVE-2022-4486
The Meteor Slides WordPress plugin through 1.5.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:21 +0000 UTC Push: 2023-01-17 01:58:24 +0000 UTC |
Live-Hack-CVE/CVE-2022-4484
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used ag CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:17 +0000 UTC Push: 2023-01-17 01:58:20 +0000 UTC |
Live-Hack-CVE/CVE-2022-4483
The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:13 +0000 UTC Push: 2023-01-17 01:58:16 +0000 UTC |
Live-Hack-CVE/CVE-2022-4482
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high priv CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:08 +0000 UTC Push: 2023-01-17 01:58:12 +0000 UTC |
Live-Hack-CVE/CVE-2022-4481
The Mesmerize Companion WordPress plugin before 1.6.135 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:05 +0000 UTC Push: 2023-01-17 01:58:07 +0000 UTC |
Live-Hack-CVE/CVE-2022-4480
The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:00 +0000 UTC Push: 2023-01-17 01:58:03 +0000 UTC |
Live-Hack-CVE/CVE-2022-4478
The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. CVE project by @Sn0wAlice
Create: 2023-01-17 01:57:55 +0000 UTC Push: 2023-01-17 01:57:59 +0000 UTC |
Live-Hack-CVE/CVE-2022-4477
The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. CVE project by @Sn0wAlice
Create: 2023-01-17 01:57:51 +0000 UTC Push: 2023-01-17 01:57:54 +0000 UTC |
Live-Hack-CVE/CVE-2022-4476
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. CVE project by @Sn0wAlice
Create: 2023-01-17 01:57:46 +0000 UTC Push: 2023-01-17 01:57:49 +0000 UTC |
Live-Hack-CVE/CVE-2022-4469
The Simple Membership WordPress plugin before 4.2.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm CVE project by @Sn0wAlice
Create: 2023-01-17 01:57:42 +0000 UTC Push: 2023-01-17 01:57:45 +0000 UTC |
Live-Hack-CVE/CVE-2022-4464
Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such CVE project by @Sn0wAlice
Create: 2023-01-17 01:57:37 +0000 UTC Push: 2023-01-17 01:57:40 +0000 UTC |
Previous
1047
1048
1049
1050
1051
1052
1053
1054
Next