Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
text vulnerabilities and exploits
(subscribe to this query)
4.8
CVSSv3
CVE-2021-24607
The Storefront Footer Text WordPress plugin up to and including 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
Wooassist Storefront Footer Text
4.3
CVSSv3
CVE-2023-3356
The Subscribers Text Counter WordPress plugin prior to 1.7.1 does not have CSRF check in place when updating its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of ...
Kreci Subscribers Text Counter
NA
CVE-2008-5486
SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Turnkeyforms Text Link Sales
1 EDB exploit
NA
CVE-2008-6963
admin.php in TurnkeyForms Text Link Sales allows remote malicious users to bypass authentication and gain administrative privileges via a direct request.
Turnkeyforms Text Link Sales
1 EDB exploit
6.1
CVSSv3
CVE-2023-0602
The Twittee Text Tweet WordPress plugin up to and including 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.
Johnniejodelljr Twittee Text Tweet
NA
CVE-2008-5487
Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote malicious users to inject arbitrary web script or HTML via the id parameter.
Turnkeyforms Text Link Sales
1 EDB exploit
NA
CVE-2005-4730
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds.
Pear Text Password 1.0
7.8
CVSSv3
CVE-2017-8368
Sublime Text 3 Build 3126 allows user-assisted malicious users to cause a denial of service or possibly have unspecified other impact via a crafted .mkv file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined...
Sublimetext Sublime Text 3 -
9.8
CVSSv3
CVE-2019-13187
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.
Symphonyextensions Rich Text Formatter
5.4
CVSSv3
CVE-2023-42371
Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote malicious user to execute arbitrary code via a crafted script to the insert link function in the editor component.
Summernote Rich Text Editor
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
man-in-the-middle
CVE-2024-34558
CVE-2024-32674
CVE-2024-34351
XPath injection
CVE-2023-45866
CVE-2024-25528
CVE-2024-25517
path traversal
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »