Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24534 1 Phonetrack 1 Phonetrack Meu Site Manager 2021-08-23 3.5 LOW 5.4 MEDIUM
The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue.
CVE-2021-24540 1 Wonderplugin 1 Wonder Video Embed 2021-08-23 3.5 LOW 5.4 MEDIUM
The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.
CVE-2021-24541 1 Wonderplugin 1 Wonder Pdf Embed 2021-08-23 3.5 LOW 5.4 MEDIUM
The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.
CVE-2021-24548 1 Mimetic 1 Mimetic Books 2021-08-23 3.5 LOW 5.4 MEDIUM
The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page.
CVE-2021-24536 1 Custom Login Redirect Project 1 Custom Login Redirect 2021-08-23 4.3 MEDIUM 6.1 MEDIUM
The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored Cross-Site Scripting issue
CVE-2021-24512 1 Videowhisper 1 Video Posts Webcam Recorder 2021-08-23 3.5 LOW 5.4 MEDIUM
The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.
CVE-2021-24411 1 Social Tape Project 1 Social Tape 2021-08-23 4.3 MEDIUM 6.1 MEDIUM
The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attack
CVE-2021-24362 1 10web 1 Photo Gallery 2021-08-23 4.3 MEDIUM 6.1 MEDIUM
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issue
CVE-2021-38708 1 Compo 1 Composr Cms 2021-08-23 3.5 LOW 5.4 MEDIUM
In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.
CVE-2021-28002 1 Textpattern 1 Textpattern 2021-08-23 3.5 LOW 5.4 MEDIUM
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting the 'Articles' page.
CVE-2021-28001 1 Textpattern 1 Textpattern 2021-08-23 3.5 LOW 5.4 MEDIUM
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting https://site.com/articles/welcome-to-your-site#comments-head.
CVE-2021-28000 1 Local Services Search Engine Management System Project 1 Local Services Search Engine Management System 2021-08-23 3.5 LOW 4.8 MEDIUM
A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloads entered into the Name and Address fields.
CVE-2021-27822 1 Vehicle Parking Management System Project 1 Vehicle Parking Management System 2021-08-23 3.5 LOW 4.8 MEDIUM
A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Category field.
CVE-2020-18748 1 Typora 1 Typora 2021-08-23 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different vulnerability from CVE-2020-18221.
CVE-2020-20645 1 Eyoucms 1 Eyoucms 2021-08-23 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
CVE-2018-6447 1 Broadcom 1 Fabric Operating System 2021-08-23 3.5 LOW 5.4 MEDIUM
A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account.
CVE-2021-37700 1 Paste-markdown Project 1 Paste-markdown 2021-08-23 4.3 MEDIUM 6.1 MEDIUM
@github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string `<table>`, a **div** is dynamically created, and the clipboard content is copied into its **innerHTML** property without any sanitization, resulting in improper execution of JavaScript in the browser of the victim (the user who pasted the code). Users directed to copy text from a malicious website and paste it into pages that utilize this library are affected. This is fixed in version 0.3.4. Refer the to the referenced GitHub Advisory for more details including an example exploit.
CVE-2021-36785 1 Miniorange 1 Saml 2021-08-20 3.5 LOW 5.4 MEDIUM
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.
CVE-2021-35955 1 Contao 1 Contao 2021-08-20 3.5 LOW 4.8 MEDIUM
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.
CVE-2021-36950 1 Microsoft 1 Dynamics 365 2021-08-20 3.5 LOW 5.4 MEDIUM
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability