Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
text vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-3356
The Subscribers Text Counter WordPress plugin prior to 1.7.1 does not have CSRF check in place when updating its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of ...
Kreci Subscribers Text Counter
NA
CVE-2023-5745
The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible ...
Halgatewood Reusable Text Blocks
3.5
CVSSv2
CVE-2021-24607
The Storefront Footer Text WordPress plugin up to and including 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
Wooassist Storefront Footer Text
10
CVSSv2
CVE-2005-4730
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds.
Pear Text Password 1.0
3.5
CVSSv2
CVE-2022-34786
Jenkins Rich Text Publisher Plugin 1.4 and previous versions does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
Jenkins Rich Text Publisher
7.2
CVSSv2
CVE-2019-16253
The Text-to-speech Engine (aka SamsungTTS) application prior to 3.0.02.7 and 3.0.00.101 for Android allows a local malicious user to escalate privileges, e.g., to system privileges. The Samsung case ID is 101755.
Samsung Text-to-speech
8 Github repositories
NA
CVE-2023-3894
Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of serv...
Fasterxml Jackson-dataformats-text
NA
CVE-2023-42371
Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote malicious user to execute arbitrary code via a crafted script to the insert link function in the editor component.
Summernote Rich Text Editor
6.8
CVSSv2
CVE-2017-8368
Sublime Text 3 Build 3126 allows user-assisted malicious users to cause a denial of service or possibly have unspecified other impact via a crafted .mkv file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined...
Sublimetext Sublime Text 3 -
NA
CVE-2023-0602
The Twittee Text Tweet WordPress plugin up to and including 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.
Johnniejodelljr Twittee Text Tweet
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »