Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-43742 | 1 Cmsimple | 1 Cmsimple | 2022-08-05 | 3.5 LOW | 5.4 MEDIUM |
CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature. | |||||
CVE-2022-23733 | 1 Github | 1 Enterprise Server | 2022-08-05 | N/A | 5.4 MEDIUM |
A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.3.11, 3.4.6 and 3.5.3. This vulnerability was reported via the GitHub Bug Bounty program. | |||||
CVE-2022-34618 | 1 Mealie Project | 1 Mealie | 2022-08-05 | N/A | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field. | |||||
CVE-2022-34619 | 1 Mealie Project | 1 Mealie | 2022-08-05 | N/A | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field. | |||||
CVE-2022-31109 | 1 Getlaminas | 1 Laminas-diactoros | 2022-08-05 | N/A | 6.1 MEDIUM |
laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behind a proxy, or can be accessed via untrusted proxies, can potentially have the host, protocol, and/or port of a `Laminas\Diactoros\Uri` instance associated with the incoming server request modified to reflect values from `X-Forwarded-*` headers. Such changes can potentially lead to XSS attacks (if a fully-qualified URL is used in links) and/or URL poisoning. Since the `X-Forwarded-*` headers do have valid use cases, particularly in clustered environments using a load balancer, the library offers mitigation measures only in the v2 releases, as doing otherwise would break these use cases immediately. Users of v2 releases from 2.11.1 can provide an additional argument to `Laminas\Diactoros\ServerRequestFactory::fromGlobals()` in the form of a `Laminas\Diactoros\RequestFilter\RequestFilterInterface` instance, including the shipped `Laminas\Diactoros\RequestFilter\NoOpRequestFilter` implementation which ignores the `X-Forwarded-*` headers. Starting in version 3.0, the library will reverse behavior to use the `NoOpRequestFilter` by default, and require users to opt-in to `X-Forwarded-*` header usage via a configured `Laminas\Diactoros\RequestFilter\LegacyXForwardedHeaderFilter` instance. Users are advised to upgrade to version 2.11.1 or later to resolve this issue. Users unable to upgrade may configure web servers to reject `X-Forwarded-*` headers at the web server level. | |||||
CVE-2022-34163 | 1 Ibm | 1 Cics Tx | 2022-08-05 | N/A | 6.1 MEDIUM |
IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229333. | |||||
CVE-2022-2328 | 1 Flexi Quote Rotator Project | 1 Flexi Quote Rotator | 2022-08-05 | N/A | 4.8 MEDIUM |
The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-2325 | 1 Securebit | 1 Invitation Based Registrations | 2022-08-05 | N/A | 4.8 MEDIUM |
The Invitation Based Registrations WordPress plugin through 2.2.84 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
CVE-2022-2305 | 1 Timersys | 1 Popups | 2022-08-05 | N/A | 4.8 MEDIUM |
The WordPress Popup WordPress plugin through 1.9.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
CVE-2022-2215 | 1 Givewp | 1 Givewp | 2022-08-05 | N/A | 4.8 MEDIUM |
The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
CVE-2022-2181 | 1 Sigmaplugin | 1 Advanced Wordpress Reset | 2022-08-05 | N/A | 6.1 MEDIUM |
The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting | |||||
CVE-2022-31148 | 1 Shopware | 1 Shopware | 2022-08-05 | N/A | 5.4 MEDIUM |
Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current version 5.7.14. You can get the update to 5.7.14 regularly via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue. | |||||
CVE-2022-2278 | 1 Fifu | 1 Featured Image From Url | 2022-08-05 | N/A | 4.8 MEDIUM |
The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not validate, sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
CVE-2021-1351 | 1 Cisco | 1 Webex Meetings | 2022-08-05 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected service. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. | |||||
CVE-2022-2170 | 1 Microsoft | 1 Microsoft Advertising Universal Event Tracking | 2022-08-05 | N/A | 4.8 MEDIUM |
The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage. | |||||
CVE-2022-36343 | 1 Ideastocode | 1 Enable Svg\, Webp \& Ico Upload | 2022-08-05 | N/A | 5.4 MEDIUM |
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress. | |||||
CVE-2022-2579 | 1 Garage Management System Project | 1 Garage Management System | 2022-08-05 | N/A | 5.4 MEDIUM |
A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument userName with the input lala<img src="" onerror=alert(1)> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2021-39348 | 1 Thimpress | 1 Learnpress | 2022-08-05 | 3.5 LOW | 4.8 MEDIUM |
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.3.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. Please note that this is seperate from CVE-2021-24702. | |||||
CVE-2022-35118 | 1 Pyrocms | 1 Pyrocms | 2022-08-04 | N/A | 6.1 MEDIUM |
PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | |||||
CVE-2022-32750 | 1 Ibm | 1 Datapower Gateway | 2022-08-04 | N/A | 5.4 MEDIUM |
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228435. |