NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11525 | CVE-2011-5270 | wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role. | 2 | 4 | Medium | 2017-01-07 | 2014-01-21 | View | |
| 11524 | CVE-2011-5269 | Cross-site scripting (XSS) vulnerability in ProjectForge before 3.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a validation message. | 2 | 3.5 | Low | 2017-01-07 | 2014-01-02 | View | |
| 11523 | CVE-2011-5268 | connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue. | 2 | 4.3 | Medium | 2017-01-07 | 2014-01-03 | View | |
| 11522 | CVE-2011-5267 | Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) to_p_dict or (2) to_r_list parameter. NOTE: this issue might be related to the htmlarea plugin and CVE-2013-5670. | 2 | 4.3 | Medium | 2017-01-07 | 2013-11-07 | View | |
| 11521 | CVE-2011-5265 | Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the snum parameter. NOTE: this has been disputed by a third party. | 2 | 4.3 | Medium | 2017-01-07 | 2013-02-15 | View |
Page 15368 of 17672, showing 5 records out of 88360 total, starting on record 76836, ending on 76840