Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-13364 | 1 Piwigo | 1 Piwigo | 2023-02-28 | 6.8 MEDIUM | 9.6 CRITICAL |
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF. | |||||
CVE-2019-13363 | 1 Piwigo | 1 Piwigo | 2023-02-28 | 6.8 MEDIUM | 9.6 CRITICAL |
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit parameter. This is exploitable via CSRF. | |||||
CVE-2020-13430 | 1 Grafana | 1 Grafana | 2023-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. | |||||
CVE-2019-18413 | 1 Typestack Class-validator Project | 1 Typestack Class-validator | 2023-02-28 | 7.5 HIGH | 9.8 CRITICAL |
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input. NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product. | |||||
CVE-2023-22868 | 3 Ibm, Linux, Microsoft | 3 Aspera Faspex, Linux Kernel, Windows | 2023-02-28 | N/A | 5.4 MEDIUM |
IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 244117. | |||||
CVE-2020-36656 | 1 Brainstormforce | 1 Spectra | 2023-02-27 | N/A | 5.4 MEDIUM |
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks. | |||||
CVE-2023-26235 | 1 Jd-gui Project | 1 Jd-gui | 2023-02-27 | N/A | 6.1 MEDIUM |
JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java. | |||||
CVE-2022-4622 | 1 Wpbrigade | 1 Login Logout Menu | 2023-02-27 | N/A | 5.4 MEDIUM |
The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |||||
CVE-2023-0966 | 1 Online Eyewear Shop Project | 1 Online Eyewear Shop | 2023-02-27 | N/A | 8.8 HIGH |
A vulnerability classified as problematic was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=orders/view_order. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221635. | |||||
CVE-2023-0442 | 1 Loan Comparison Project | 1 Loan Comparison | 2023-02-27 | N/A | 6.1 MEDIUM |
The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL. | |||||
CVE-2023-0429 | 1 Kibokolabs | 1 Watu Quiz | 2023-02-27 | N/A | 4.8 MEDIUM |
The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2023-0378 | 1 Greenshiftwp | 1 Greenshift - Animation And Page Builder Blocks | 2023-02-27 | N/A | 5.4 MEDIUM |
The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2023-0380 | 1 Sandhillsdev | 1 Easy Digital Downloads | 2023-02-27 | N/A | 5.4 MEDIUM |
The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2023-0428 | 1 Kibokolabs | 1 Watu Quiz | 2023-02-27 | N/A | 6.1 MEDIUM |
The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |||||
CVE-2023-0419 | 1 Smg-webdesign | 1 Shortcode For Font Awesome | 2023-02-27 | N/A | 5.4 MEDIUM |
The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2023-0375 | 1 Bootstrapped | 1 Easy Affiliate Links | 2023-02-27 | N/A | 5.4 MEDIUM |
The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2023-0285 | 1 Devowl | 1 Real Media Library | 2023-02-27 | N/A | 5.4 MEDIUM |
The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2023-0372 | 1 Embedsocial | 1 Embedstories | 2023-02-27 | N/A | 5.4 MEDIUM |
The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |||||
CVE-2023-0366 | 1 Quick-plugins | 1 Loan Comparison | 2023-02-27 | N/A | 5.4 MEDIUM |
The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |||||
CVE-2023-0371 | 1 Embedsocial | 1 Embedsocial | 2023-02-27 | N/A | 5.4 MEDIUM |
The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks |