CVE-2017-8103
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
Read MoreIn MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
Read MoreIn MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
Read MoreThere is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.
Read MoreXSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.
Read MoreStored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin’s cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a...
Read More