Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-23060 | 1 Shopizer | 1 Shopizer | 2022-05-09 | 3.5 LOW | 4.8 MEDIUM |
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab | |||||
CVE-2022-29969 | 1 Mediawiki | 1 Rss For Mediawiki | 2022-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true). | |||||
CVE-2022-20629 | 1 Cisco | 1 Firepower Management Center | 2022-05-09 | 3.5 LOW | 5.4 MEDIUM |
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. | |||||
CVE-2022-20628 | 1 Cisco | 1 Firepower Management Center | 2022-05-09 | 3.5 LOW | 5.4 MEDIUM |
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. | |||||
CVE-2022-20627 | 1 Cisco | 1 Firepower Management Center | 2022-05-09 | 3.5 LOW | 5.4 MEDIUM |
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. | |||||
CVE-2022-20740 | 1 Cisco | 1 Firepower Management Center | 2022-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information. | |||||
CVE-2022-1046 | 1 Vfbpro | 1 Visual Form Builder | 2022-05-09 | 3.5 LOW | 4.8 MEDIUM |
The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0428 | 1 Keywordrush | 1 Content Egg | 2022-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-0418 | 1 Event List Project | 1 Event List | 2022-05-09 | 3.5 LOW | 4.8 MEDIUM |
The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed | |||||
CVE-2021-43932 | 1 Smartptt | 1 Smartptt Scada | 2022-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page. | |||||
CVE-2022-0662 | 1 Ajdg | 1 Adrotate | 2022-05-09 | 3.5 LOW | 4.8 MEDIUM |
The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0649 | 1 Ajdg | 1 Adrotate | 2022-05-09 | 3.5 LOW | 4.8 MEDIUM |
The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-1250 | 1 Lifterlms | 1 Lifterlms | 2022-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2022-1255 | 1 Codection | 1 Import And Export Users And Customers | 2022-05-09 | 3.5 LOW | 4.8 MEDIUM |
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues | |||||
CVE-2022-29907 | 1 Mediawiki | 1 Mediawiki | 2022-05-06 | 4.3 MEDIUM | 6.1 MEDIUM |
The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise link messages. | |||||
CVE-2022-24873 | 1 Shopware | 1 Shopware | 2022-05-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin. | |||||
CVE-2022-29152 | 1 Ericom | 1 Powerterm Webconnect | 2022-05-06 | 4.3 MEDIUM | 6.1 MEDIUM |
The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page. | |||||
CVE-2022-29584 | 1 Mahara | 1 Mahara | 2022-05-06 | 3.5 LOW | 5.4 MEDIUM |
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action. | |||||
CVE-2022-28477 | 1 Wbce | 1 Wbce Cms | 2022-05-06 | 4.3 MEDIUM | 6.1 MEDIUM |
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). | |||||
CVE-2022-28454 | 1 Limbas | 1 Limbas | 2022-05-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS). |