Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-25115 | 1 Wp Photo Album Plus Project | 1 Wp Photo Album Plus | 2022-02-18 | 3.5 LOW | 6.4 MEDIUM |
The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel. | |||||
CVE-2021-25050 | 1 Wpchill | 1 Remove Footer Credit | 2022-02-18 | 3.5 LOW | 4.8 MEDIUM |
The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | |||||
CVE-2021-24563 | 1 Frontend Uploader Project | 1 Frontend Uploader | 2022-02-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly | |||||
CVE-2022-0201 | 2 Permalink Manager Lite Project, Permalink Manager Project | 2 Permalink Manager Lite, Permalink Manager | 2022-02-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2022-0176 | 1 Wpbeaveraddons | 1 Powerpack Lite For Beaver Builder | 2022-02-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-0200 | 1 Themify | 1 Portfolio Post | 2022-02-18 | 3.5 LOW | 5.4 MEDIUM |
Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting | |||||
CVE-2022-0212 | 1 10web | 1 Spidercalendar | 2022-02-18 | 4.3 MEDIUM | 6.1 MEDIUM |
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue. | |||||
CVE-2021-46557 | 1 Vicidial | 1 Vicidial | 2022-02-18 | 3.5 LOW | 5.4 MEDIUM |
Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs. | |||||
CVE-2021-4046 | 1 Tcman | 1 Gim | 2022-02-18 | 3.5 LOW | 5.4 MEDIUM |
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data. | |||||
CVE-2022-23312 | 1 Siemens | 1 Spectrum Power 4 | 2022-02-18 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP9 Security Patch 1). The integrated web application "Online Help" in affected product contains a Cross-Site Scripting (XSS) vulnerability that could be exploited if unsuspecting users are tricked into accessing a malicious link. | |||||
CVE-2021-42940 | 1 Projeqtor | 1 Projeqtor | 2022-02-17 | 3.5 LOW | 9.9 CRITICAL |
A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious JavaScript code. | |||||
CVE-2020-13669 | 1 Drupal | 1 Drupal | 2022-02-17 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6. | |||||
CVE-2022-0020 | 1 Paloaltonetworks | 1 Cortex Xsoar | 2022-02-17 | 3.5 LOW | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888. | |||||
CVE-2021-46355 | 1 Factorfx | 1 Ocs Inventory | 2022-02-17 | 3.5 LOW | 5.4 MEDIUM |
OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manipulate the name of some device on your computer, such as a printer, replacing the device name with some malicious code that allows the execution of Stored Cross-site Scripting (XSS). | |||||
CVE-2021-41445 | 1 Dlink | 2 Dir-x1860, Dir-x1860 Firmware | 2022-02-17 | 4.3 MEDIUM | 6.1 MEDIUM |
A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim. | |||||
CVE-2022-0558 | 1 Microweber | 1 Microweber | 2022-02-17 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. | |||||
CVE-2022-23049 | 1 Exponentcms | 1 Exponent Cms | 2022-02-16 | 3.5 LOW | 5.4 MEDIUM |
Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session. | |||||
CVE-2021-44912 | 1 Xpressengine | 1 Xpressengine | 2022-02-16 | 3.5 LOW | 5.4 MEDIUM |
In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type, uploading HTML-type files leads to stored XSS vulnerabilities. If the .htaccess configuration is improper, for example before the XE 1.11.2 version, you can upload the PHP type file to GETSHELL. | |||||
CVE-2021-44911 | 1 Xpressengine | 1 Xpressengine | 2022-02-16 | 3.5 LOW | 5.4 MEDIUM |
XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php. When uploading the Mouse over button and When selected button, there is no restriction on the file suffix, which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type, uploading HTML-type files leads to stored XSS vulnerabilities. | |||||
CVE-2021-44969 | 1 Taogogo | 1 Taocms | 2022-02-16 | 3.5 LOW | 4.8 MEDIUM |
Taocms v3.0.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Management Column component. |