Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Tablesome before 1.0.9 is susceptible to cross-site scripting via the tab parameter due to insufficient input sanitization and output escaping. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1890.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-0763 | Clock In Portal <= 2.1 - Holidays Deletion via CSRF | |
| CVE-2023-1207 | HTTP Headers < 1.18.8 - Admin+ SQL Injection | |
| CVE-2023-1549 | Ad Inserter < 2.7.27 - Admin+ PHP Object Injection | |
| CVE-2023-0600 | WP Visitor Statistics (Real Time Traffic) < 6.9 - Unauthenticated SQLi | |
| CVE-2023-0762 | Clock In Portal <= 2.1 - Designation Deletion via CSRF | |
| CVE-2023-1915 | Thumbnail carousel slider < 1.1.10 - Reflected XSS | |
| CVE-2023-0892 | BizLibrary <= 1.1 - Admin+ Stored XSS | |
| CVE-2023-2180 | KIWIZ Invoices Certification & PDF System <= 2.1.3 - Unauthenticated Arbitrary File Downlo | |
| CVE-2023-2179 | WooCommerce Order Status Change Notifier <= 1.1.0 - Subscriber+ Arbitrary Order Status Upd | |
| CVE-2023-1596 | tagDiv Composer < 4.0 - Reflected Cross-site Scripting | |
| CVE-2023-0520 | RapidExpCart <= 1.0 - Stored XSS via CSRF | |
| CVE-2023-0233 | ActiveCampaign < 8.1.12 - Contributor+ Stored XSS | |
| CVE-2023-0812 | Active Directory Integration / LDAP Integration < 4.1.1 - Unauthenticated Data Disclosure | |
| CVE-2023-0490 | f(x) TOC <= 1.1.0 - Contributor+ Stored XSS | |
| CVE-2023-0644 | PushAssist <= 3.0.8 - Reflected Cross-Site Scripting | |
| CVE-2023-2009 | Pretty Url <= 1.5.4 - Admin+ Stored XSS in plugin settings | |
| CVE-2023-1019 | Help Desk WP <= 1.2.0 - Editor+ Stored XSS | |
| CVE-2023-0761 | Clock In Portal <= 2.1 - Staff Deletion via CSRF | |
| CVE-2022-4774 | Bit Form < 1.9 - RCE via Unauthenticated Arbitrary File Upload | |
| CVE-2023-1835 | Ninja Forms < 3.6.22 - Reflected XSS |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet