NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85045 | CVE-2017-8100 | There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings. | 2 | 4.3 | Medium | 2017-05-07 | 2017-05-02 | View | |
85044 | CVE-2017-8099 | There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request. | 2 | 5.8 | Medium | 2017-05-07 | 2017-04-28 | View | |
85043 | CVE-2017-8098 | e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker. | 2 | 4.3 | Medium | 2017-05-07 | 2017-04-29 | View | |
85042 | CVE-2017-8085 | In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php. | 2 | 4.3 | Medium | 2017-05-07 | 2017-04-28 | View | |
85041 | CVE-2017-8082 | concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators. | 2 | 4.3 | Medium | 2017-05-07 | 2017-04-27 | View |
Page 664 of 17672, showing 5 records out of 88360 total, starting on record 3316, ending on 3320