Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-35249 | 1 Elkarbackup | 1 Elkarbackup | 2021-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature. | |||||
CVE-2020-27406 | 1 Dynpg | 1 Dynpg | 2021-11-02 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname. | |||||
CVE-2021-33611 | 1 Vaadin | 2 Vaadin, Vaadin-menu-bar | 2021-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL | |||||
CVE-2021-41310 | 1 Atlassian | 1 Jira Software Data Center | 2021-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11, and from version 8.14.0 before 8.19.1. | |||||
CVE-2021-24624 | 1 Sonaar | 1 Mp3 Audio Player For Music\, Radio \& Podcast | 2021-11-02 | 3.5 LOW | 4.8 MEDIUM |
The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks | |||||
CVE-2015-20019 | 1 Content Text Slider On Post Project | 1 Content Text Slider On Post | 2021-11-02 | 3.5 LOW | 5.4 MEDIUM |
The Content text slider on post WordPress plugin before 6.9 does not sanitise and escape the Title and Message/Content settings, which could lead to Cross-Site Scripting issues | |||||
CVE-2021-39346 | 1 Supsystic | 1 Easy Google Maps | 2021-11-02 | 2.1 LOW | 4.8 MEDIUM |
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. | |||||
CVE-2021-39340 | 1 Bracketspace | 1 Notification | 2021-11-02 | 2.1 LOW | 4.8 MEDIUM |
The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 7.2.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. | |||||
CVE-2021-38356 | 1 Nextscripts | 1 Social Networks Auto Poster | 2021-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript in $_POST['page']. | |||||
CVE-2021-24813 | 1 E-dynamics | 1 Events Made Easy | 2021-11-02 | 3.5 LOW | 4.8 MEDIUM |
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2021-24794 | 1 Connections-pro | 1 Connections Business Directory | 2021-11-02 | 3.5 LOW | 4.8 MEDIUM |
The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24793 | 1 Etruel | 1 Wpematico Rss Feed Fetcher | 2021-11-02 | 3.5 LOW | 4.8 MEDIUM |
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24789 | 1 Flat Preloader Project | 1 Flat Preloader | 2021-11-02 | 3.5 LOW | 4.8 MEDIUM |
The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |||||
CVE-2021-24773 | 1 Wpdownloadmanager | 1 Wordpress Download Manager | 2021-11-02 | 3.5 LOW | 4.8 MEDIUM |
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed | |||||
CVE-2021-24723 | 1 Wpreactions | 1 Wp Reactions Lite | 2021-11-02 | 3.5 LOW | 5.4 MEDIUM |
The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages. | |||||
CVE-2021-24716 | 1 Webnus | 1 Modern Events Calendar Lite | 2021-11-02 | 3.5 LOW | 5.4 MEDIUM |
The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin. | |||||
CVE-2021-24715 | 1 Wp Sitemap Page Project | 1 Wp Sitemap Page | 2021-11-02 | 3.5 LOW | 4.8 MEDIUM |
The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-36551 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2021-11-02 | 3.5 LOW | 5.4 MEDIUM |
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module. | |||||
CVE-2019-15116 | 1 Sandhillsdev | 1 Easy Digital Downloads | 2021-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging. | |||||
CVE-2021-24682 | 1 Wpkube | 1 Cool Tag Cloud | 2021-11-02 | 3.5 LOW | 5.4 MEDIUM |
The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. |