Security
Headlines
HeadlinesLatestCVEs

Tag

#google

CVE-2015-9304: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.

CVE
#sql#xss#vulnerability#web#ios#android#windows#google#js#git#java#wordpress#php#perl#auth#sap#ssl
CVE-2019-14787: Newsletters

The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.

CVE-2019-14792

The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.

CVE-2019-10371: Jenkins Security Advisory 2019-08-07

A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.