Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24560 | 1 Tipsandtricks-hq | 1 Software License Manager | 2021-09-23 | 4.3 MEDIUM | 6.1 MEDIUM |
The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2020-19148 | 1 Jflyfox | 1 Jfinal Cms | 2021-09-22 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'. | |||||
CVE-2020-19156 | 1 Ari-soft | 1 Ari Adminer | 2021-09-22 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called. | |||||
CVE-2020-19158 | 1 S-cms | 1 S-cms | 2021-09-22 | 3.5 LOW | 5.4 MEDIUM |
Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'. | |||||
CVE-2020-19157 | 1 Wenkucms Project | 1 Wenkucms | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'. | |||||
CVE-2021-21489 | 1 Sap | 1 Netweaver Enterprise Portal | 2021-09-22 | 3.5 LOW | 4.8 MEDIUM |
SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with administrative privileges to store a malicious script on the portal. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of portal content. | |||||
CVE-2021-32202 | 1 Cs-cart | 1 Cs-cart | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page. | |||||
CVE-2021-40214 | 1 Gibbonedu | 1 Gibbon | 2021-09-22 | 3.5 LOW | 5.4 MEDIUM |
Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component. | |||||
CVE-2021-38325 | 1 User-activation-email Project | 1 User-activation-email | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter found in the ~/user-activation-email.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.0. | |||||
CVE-2021-29643 | 1 Paessler | 1 Prtg Network Monitor | 2021-09-22 | 3.5 LOW | 5.4 MEDIUM |
PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance. | |||||
CVE-2021-22528 | 1 Microfocus | 1 Access Manager | 2021-09-22 | 3.5 LOW | 5.4 MEDIUM |
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 | |||||
CVE-2021-38316 | 1 Wp Academic People List Project | 1 Wp Academic People List | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name parameter in the ~/admin-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.4.1. | |||||
CVE-2021-38317 | 1 Kibokolabs | 1 Konnichiwa | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in the ~/views/subscriptions.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.8.3. | |||||
CVE-2021-38318 | 1 3d Cover Carousel Project | 1 3d Cover Carousel | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cover-carousel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0. | |||||
CVE-2021-38319 | 1 Windyroad | 1 More From Google | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/morefromgoogle.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.2. | |||||
CVE-2021-38320 | 1 Simplesamlphp Authentication Project | 1 Simplesamlphp Authentication | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0. | |||||
CVE-2021-38322 | 1 Twitter Friends Widget Project | 1 Twitter Friends Widget | 2021-09-22 | 4.3 MEDIUM | 6.1 MEDIUM |
The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.1. | |||||
CVE-2013-6853 | 3 Apple, Mozilla, Yahoo | 3 Macos, Firefox, Toolbar | 2021-09-22 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim. | |||||
CVE-2021-40223 | 1 Rittal | 2 Cmc Pu Iii 7030.000, Cmc Pu Iii 7030.000 Firmware | 2021-09-22 | 3.5 LOW | 5.4 MEDIUM |
Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog). This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts). The XSS payload will be triggered when the user accesses some specific sections of the application. | |||||
CVE-2021-38331 | 1 Wp-t-wap Project | 1 Wp-t-wap | 2021-09-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.13.2. |