Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-45281 | 1 Quickbox | 1 Quickbox | 2022-02-11 | 4.3 MEDIUM | 6.1 MEDIUM |
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized. | |||||
CVE-2022-22142 | 1 Econosys-system | 1 Php Mailform | 2022-02-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected cross-site scripting vulnerability in the checkbox of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2022-21805 | 1 Econosys-system | 1 Php Mailform | 2022-02-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected cross-site scripting vulnerability in the attached file name of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2021-25077 | 1 Visser | 1 Store Toolkit For Woocommerce | 2022-02-11 | 4.3 MEDIUM | 6.1 MEDIUM |
The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25029 | 1 Cluevo | 1 Learning Management System | 2022-02-11 | 3.5 LOW | 4.8 MEDIUM |
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2022-0502 | 1 Livehelperchat | 1 Live Helper Chat | 2022-02-10 | 3.5 LOW | 5.4 MEDIUM |
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |||||
CVE-2022-0501 | 1 Beanstalk Console Project | 1 Beanstalk Console | 2022-02-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12. | |||||
CVE-2021-25103 | 1 Gtranslate | 1 Translate Wordpress With Gtranslate | 2022-02-10 | 2.6 LOW | 4.7 MEDIUM |
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY | |||||
CVE-2021-25106 | 1 Wpeka | 1 Wplegalpages | 2022-02-10 | 3.5 LOW | 5.4 MEDIUM |
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting | |||||
CVE-2021-24880 | 1 Supportcandy | 1 Supportcandy | 2022-02-10 | 3.5 LOW | 5.4 MEDIUM |
The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks | |||||
CVE-2021-25105 | 1 Ivorysearch | 1 Ivory Search | 2022-02-10 | 3.5 LOW | 4.8 MEDIUM |
The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2022-0148 | 1 Premio | 1 Mystickyelements | 2022-02-10 | 3.5 LOW | 5.4 MEDIUM |
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page. | |||||
CVE-2022-0149 | 1 Visser | 1 Store Exporter For Woocommerce | 2022-02-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page. | |||||
CVE-2021-37402 | 1 Open-xchange | 1 Open-xchange Appsuite | 2022-02-10 | 4.3 MEDIUM | 6.1 MEDIUM |
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled. | |||||
CVE-2021-26698 | 1 Open-xchange | 1 Open-xchange Appsuite | 2022-02-10 | 4.3 MEDIUM | 6.1 MEDIUM |
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and the dl parameter is used. | |||||
CVE-2021-24878 | 1 Supportcandy | 1 Supportcandy | 2022-02-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2021-35479 | 1 Nagios | 1 Log Server | 2022-02-10 | 3.5 LOW | 5.4 MEDIUM |
Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page. | |||||
CVE-2021-35478 | 1 Nagios | 1 Log Server | 2022-02-10 | 3.5 LOW | 5.4 MEDIUM |
Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page. | |||||
CVE-2009-3856 | 1 Twilightcms | 1 Twilight Cms | 2022-02-10 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2022-0437 | 1 Karma Project | 1 Karma | 2022-02-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. |