NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85047 | CVE-2017-8102 | Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a set_config error in that plugin. | 2 | 3.5 | Low | 2017-05-07 | 2017-04-28 | View | |
85046 | CVE-2017-8101 | There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request. | 2 | 6.8 | Medium | 2017-05-07 | 2017-04-27 | View | |
85045 | CVE-2017-8100 | There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings. | 2 | 4.3 | Medium | 2017-05-07 | 2017-05-02 | View | |
85044 | CVE-2017-8099 | There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request. | 2 | 5.8 | Medium | 2017-05-07 | 2017-04-28 | View | |
85043 | CVE-2017-8098 | e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker. | 2 | 4.3 | Medium | 2017-05-07 | 2017-04-29 | View |
Page 196 of 17672, showing 5 records out of 88360 total, starting on record 976, ending on 980