Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-2186 | 1 Bracketspace | 1 Simple Post Notes | 2022-07-18 | 3.5 LOW | 4.8 MEDIUM |
The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-2187 | 1 Contact Form 7 Captcha Project | 1 Contact Form 7 Captcha | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |||||
CVE-2022-2173 | 1 Sigmaplugin | 1 Advanced Database Cleaner | 2022-07-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting | |||||
CVE-2020-35437 | 1 Intelliants | 1 Subrion Cms | 2022-07-17 | 4.3 MEDIUM | 6.1 MEDIUM |
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI. | |||||
CVE-2020-15364 | 1 Nexos Project | 1 Nexos | 2022-07-17 | 4.3 MEDIUM | 6.1 MEDIUM |
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS. | |||||
CVE-2022-2363 | 1 Simple Parking Management System Project | 1 Simple Parking Management System | 2022-07-15 | 3.5 LOW | 4.6 MEDIUM |
A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Parking Management System 1.0. Affected by this issue is some unknown functionality of the file /ci_spms/admin/search/searching/. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2022-2364 | 1 Simple Parking Management System Project | 1 Simple Parking Management System | 2022-07-15 | 3.5 LOW | 5.4 MEDIUM |
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Parking Management System 1.0. This affects an unknown part of the file /ci_spms/admin/category. The manipulation of the argument vehicle_type with the input "><script>alert("XSS")</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2022-31654 | 1 Vmware | 1 Vrealize Log Insight | 2022-07-15 | 3.5 LOW | 5.4 MEDIUM |
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations. | |||||
CVE-2022-31655 | 1 Vmware | 1 Vrealize Log Insight | 2022-07-15 | 3.5 LOW | 5.4 MEDIUM |
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts. | |||||
CVE-2022-32115 | 1 Withknown | 1 Known | 2022-07-15 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file. | |||||
CVE-2022-31290 | 1 Withknown | 1 Known | 2022-07-15 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field. | |||||
CVE-2022-2089 | 1 Bold-themes | 1 Bold Page Builder | 2022-07-15 | 3.5 LOW | 4.8 MEDIUM |
The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |||||
CVE-2022-2093 | 1 Ninjateam | 1 Wp Duplicate Page | 2022-07-15 | 3.5 LOW | 4.8 MEDIUM |
The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |||||
CVE-2022-2050 | 1 Maxfoundry | 1 Wp-paginate | 2022-07-15 | 3.5 LOW | 4.8 MEDIUM |
The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed | |||||
CVE-2022-1951 | 1 Kitestudio | 1 Core Plugin For Kitestudio Themes | 2022-07-15 | 4.3 MEDIUM | 6.1 MEDIUM |
The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated users when a premium theme from the vendor is active, leading to a Reflected Cross-Site Scripting. | |||||
CVE-2022-1894 | 1 Sygnoos | 1 Popup Builder | 2022-07-15 | 3.5 LOW | 4.8 MEDIUM |
The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed | |||||
CVE-2022-32308 | 1 Ublock Origin Project | 1 Ublock Origin | 2022-07-15 | N/A | 6.1 MEDIUM |
Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitrary code via a spoofed 'MessageSender.url' to the browser renderer process. | |||||
CVE-2022-22682 | 1 Synology | 1 Calendar | 2022-07-15 | 3.5 LOW | 5.4 MEDIUM |
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2022-1546 | 1 Visser | 1 Woocommerce - Product Importer | 2022-07-15 | 4.3 MEDIUM | 6.1 MEDIUM |
The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-1474 | 1 Wp-eventmanager | 1 Wp Event Manager | 2022-07-15 | 4.3 MEDIUM | 6.1 MEDIUM |
The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting |