Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24560 1 Tipsandtricks-hq 1 Software License Manager 2021-09-23 4.3 MEDIUM 6.1 MEDIUM
The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
CVE-2020-19148 1 Jflyfox 1 Jfinal Cms 2021-09-22 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
CVE-2020-19156 1 Ari-soft 1 Ari Adminer 2021-09-22 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.
CVE-2020-19158 1 S-cms 1 S-cms 2021-09-22 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'.
CVE-2020-19157 1 Wenkucms Project 1 Wenkucms 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.
CVE-2021-21489 1 Sap 1 Netweaver Enterprise Portal 2021-09-22 3.5 LOW 4.8 MEDIUM
SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with administrative privileges to store a malicious script on the portal. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of portal content.
CVE-2021-32202 1 Cs-cart 1 Cs-cart 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page.
CVE-2021-40214 1 Gibbonedu 1 Gibbon 2021-09-22 3.5 LOW 5.4 MEDIUM
Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.
CVE-2021-38325 1 User-activation-email Project 1 User-activation-email 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter found in the ~/user-activation-email.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.0.
CVE-2021-29643 1 Paessler 1 Prtg Network Monitor 2021-09-22 3.5 LOW 5.4 MEDIUM
PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.
CVE-2021-22528 1 Microfocus 1 Access Manager 2021-09-22 3.5 LOW 5.4 MEDIUM
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-38316 1 Wp Academic People List Project 1 Wp Academic People List 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name parameter in the ~/admin-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.4.1.
CVE-2021-38317 1 Kibokolabs 1 Konnichiwa 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in the ~/views/subscriptions.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.8.3.
CVE-2021-38318 1 3d Cover Carousel Project 1 3d Cover Carousel 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cover-carousel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.
CVE-2021-38319 1 Windyroad 1 More From Google 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/morefromgoogle.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.2.
CVE-2021-38320 1 Simplesamlphp Authentication Project 1 Simplesamlphp Authentication 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0.
CVE-2021-38322 1 Twitter Friends Widget Project 1 Twitter Friends Widget 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.1.
CVE-2013-6853 3 Apple, Mozilla, Yahoo 3 Macos, Firefox, Toolbar 2021-09-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim.
CVE-2021-40223 1 Rittal 2 Cmc Pu Iii 7030.000, Cmc Pu Iii 7030.000 Firmware 2021-09-22 3.5 LOW 5.4 MEDIUM
Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog). This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts). The XSS payload will be triggered when the user accesses some specific sections of the application.
CVE-2021-38331 1 Wp-t-wap Project 1 Wp-t-wap 2021-09-21 4.3 MEDIUM 6.1 MEDIUM
The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.13.2.