Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-4707 | 1 Ibm | 1 Api Connect | 2021-08-10 | 3.5 LOW | 5.4 MEDIUM |
IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187370. | |||||
CVE-2021-33337 | 1 Liferay | 2 Dxp, Liferay Portal | 2021-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter. | |||||
CVE-2021-35463 | 1 Liferay | 1 Liferay Portal | 2021-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. | |||||
CVE-2021-24468 | 1 Bozdoz | 1 Leaflet Map | 2021-08-10 | 3.5 LOW | 5.4 MEDIUM |
The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues | |||||
CVE-2021-24470 | 1 Yada Wiki Project | 1 Yada Wiki | 2021-08-10 | 3.5 LOW | 5.4 MEDIUM |
The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue | |||||
CVE-2021-24478 | 1 Bookshelf Project | 1 Bookshelf | 2021-08-10 | 3.5 LOW | 5.4 MEDIUM |
The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue | |||||
CVE-2021-24479 | 1 Drawblog Project | 1 Drawblog | 2021-08-10 | 3.5 LOW | 4.8 MEDIUM |
The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue | |||||
CVE-2021-24480 | 1 Event Geek Project | 1 Event Geek | 2021-08-10 | 3.5 LOW | 4.8 MEDIUM |
The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting it in the page, leading to an authenticated (admin+) stored Cross-Site Scripting issue | |||||
CVE-2021-24488 | 1 Pickplugins | 1 Post Grid | 2021-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues | |||||
CVE-2021-24496 | 1 Community Events Project | 1 Community Events | 2021-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator | |||||
CVE-2021-37216 | 1 Qsan | 4 Xn8008t, Xn8008t Firmware, Xn8024r and 1 more | 2021-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data. | |||||
CVE-2021-24450 | 1 Profilepress | 1 Profilepress | 2021-08-10 | 3.5 LOW | 4.8 MEDIUM |
The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and outputting them back in the page, allowing high privilege users such as admin to set JavaScript payloads in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue | |||||
CVE-2021-24481 | 1 Any Hostname Project | 1 Any Hostname | 2021-08-10 | 3.5 LOW | 4.8 MEDIUM |
The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an authenticated stored XSS issue as high privilege users are able to set XSS payloads in it | |||||
CVE-2021-24498 | 1 Dwbooster | 1 Calendar Event Multi View | 2021-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue. | |||||
CVE-2021-24503 | 1 Thememason | 1 Popular Brand Icons - Simple Icons | 2021-08-10 | 3.5 LOW | 5.4 MEDIUM |
The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability. | |||||
CVE-2021-24476 | 1 Steam Group Viewer Project | 1 Steam Group Viewer | 2021-08-10 | 3.5 LOW | 5.4 MEDIUM |
The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue | |||||
CVE-2021-24464 | 1 Wpdevart | 1 Youtube Embed\, Playlist And Popup | 2021-08-10 | 3.5 LOW | 5.4 MEDIUM |
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue. | |||||
CVE-2021-34630 | 1 Gtranslate | 1 Gtranslate | 2021-08-10 | 4.3 MEDIUM | 6.1 MEDIUM |
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution. | |||||
CVE-2021-24455 | 1 Themeum | 1 Tutor Lms | 2021-08-09 | 3.5 LOW | 5.4 MEDIUM |
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by users as low as Tutor Instructor. This lead to a Stored Cross-Site Scripting issue, which is triggered when viewing the Announcements list, and could result in privilege escalation when viewed by an admin. | |||||
CVE-2021-24448 | 1 Cozmoslabs | 1 Profile Builder | 2021-08-09 | 3.5 LOW | 4.8 MEDIUM |
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue |