Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-25303 | 1 Whoogle-search Project | 1 Whoogle-search | 2022-07-19 | 4.3 MEDIUM | 6.1 MEDIUM |
The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the [flask.render_template](https://flask.palletsprojects.com/en/2.1.x/api/flask.render_template) function. However, the error_message is rendered using the [| safe filter](https://jinja.palletsprojects.com/en/3.1.x/templates/working-with-automatic-escaping), meaning the user input is not escaped. | |||||
CVE-2020-35774 | 1 Twitter | 1 Twitter-server | 2022-07-19 | 3.5 LOW | 5.4 MEDIUM |
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint. | |||||
CVE-2022-2100 | 1 Wpzinc | 1 Page Generator | 2022-07-19 | 3.5 LOW | 4.8 MEDIUM |
The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-25875 | 1 Svelte | 1 Svelte | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function. | |||||
CVE-2022-31904 | 1 Uberrider | 1 Mediacenter | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php. | |||||
CVE-2021-39015 | 3 Ibm, Linux, Microsoft | 3 Engineering Lifecycle Optimization Publishing, Linux Kernel, Windows | 2022-07-18 | N/A | 5.4 MEDIUM |
IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213655. | |||||
CVE-2021-43702 | 1 Asus | 186 4g-ac53u, 4g-ac53u Firmware, 4g-ac68u and 183 more | 2022-07-18 | 3.5 LOW | 9.0 CRITICAL |
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |||||
CVE-2022-2090 | 1 Flycart | 1 Discount Rules For Woocommerce | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back in an attribute of the plugin's discount rule page, leading to Reflected Cross-Site Scripting | |||||
CVE-2022-2092 | 1 Wpovernight | 1 Woocommerce Pdf Invoices\& Packing Slips | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks. | |||||
CVE-2022-1933 | 1 Collect And Deliver Interface For Woocommerce Project | 1 Collect And Deliver Interface For Woocommerce | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-32318 | 1 Fast Food Ordering System Project | 1 Fast Food Ordering System | 2022-07-18 | 3.5 LOW | 5.4 MEDIUM |
Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category. | |||||
CVE-2022-2146 | 1 Import Csv Files Project | 1 Import Csv Files | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting | |||||
CVE-2022-2118 | 1 Tooltulips | 1 404s | 2022-07-18 | 3.5 LOW | 4.8 MEDIUM |
The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-2114 | 1 Supsystic | 1 Data Tables Generator | 2022-07-18 | 3.5 LOW | 4.8 MEDIUM |
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
CVE-2022-2169 | 1 Dwbooster | 1 Loading Page With Loading Screen | 2022-07-18 | 3.5 LOW | 4.8 MEDIUM |
The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-2151 | 1 Emarketdesign | 1 Best Contact Management Software | 2022-07-18 | 3.5 LOW | 4.8 MEDIUM |
The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-2168 | 1 Wpdownloadmanager | 1 Download Manager | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting | |||||
CVE-2022-2149 | 1 Very Simple Breadcrumb Project | 1 Very Simple Breadcrumb | 2022-07-18 | 3.5 LOW | 4.8 MEDIUM |
The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-2148 | 1 Linkedin Company Updates Project | 1 Linkedin Company Updates | 2022-07-18 | 3.5 LOW | 4.8 MEDIUM |
The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-2194 | 1 Tipsandtricks-hq | 1 Accept Stripe | 2022-07-18 | 3.5 LOW | 4.8 MEDIUM |
The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. |