Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24313 | 1 Goprayer | 1 Wp Prayer | 2021-06-11 | 3.5 LOW | 5.4 MEDIUM |
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads. | |||||
CVE-2021-24331 | 1 Smooth Scroll Page Up\/down Buttons Project | 1 Smooth Scroll Page Up\/down Buttons | 2021-06-11 | 3.5 LOW | 4.8 MEDIUM |
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them | |||||
CVE-2021-24330 | 1 Cartflows | 1 Funnel Builder | 2021-06-11 | 3.5 LOW | 4.8 MEDIUM |
The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole website depending on the settings used. | |||||
CVE-2021-24334 | 1 Connekthq | 1 Instant Images - One Click Unsplash Uploads | 2021-06-11 | 3.5 LOW | 5.4 MEDIUM |
The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Scripting issue. | |||||
CVE-2020-24663 | 1 Tracefinanacial | 1 Crestbridge | 2021-06-11 | 3.5 LOW | 5.4 MEDIUM |
Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03. | |||||
CVE-2020-24668 | 1 Tracefinancial | 1 Crestbridge | 2021-06-11 | 3.5 LOW | 5.4 MEDIUM |
Trace Financial Crest Bridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03. | |||||
CVE-2021-31830 | 1 Mcafee | 1 Database Security | 2021-06-11 | 3.5 LOW | 4.8 MEDIUM |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database. | |||||
CVE-2021-24317 | 1 Purethemes | 1 Listeo | 2021-06-11 | 4.3 MEDIUM | 6.1 MEDIUM |
The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues | |||||
CVE-2021-24335 | 1 Smartdatasoft | 1 Car Repair Services \& Auto Mechanic | 2021-06-11 | 4.3 MEDIUM | 6.1 MEDIUM |
The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue | |||||
CVE-2021-24322 | 1 Deliciousbrains | 1 Database Backup | 2021-06-11 | 3.5 LOW | 5.4 MEDIUM |
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue. | |||||
CVE-2020-36384 | 1 Pagelayer | 1 Pagelayer | 2021-06-11 | 4.3 MEDIUM | 6.1 MEDIUM |
PageLayer before 1.3.5 allows reflected XSS via color settings. | |||||
CVE-2021-26584 | 1 Hp | 1 Oneview For Vmware Vcenter | 2021-06-11 | 4.3 MEDIUM | 6.1 MEDIUM |
A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC). | |||||
CVE-2021-25932 | 1 Opennms | 2 Meridian, Opennms | 2021-06-11 | 3.5 LOW | 5.4 MEDIUM |
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `userID` parameter. Due to this flaw an attacker could inject an arbitrary script which will be stored in the database. | |||||
CVE-2020-36383 | 1 Pagelayer | 1 Pagelayer | 2021-06-11 | 4.3 MEDIUM | 6.1 MEDIUM |
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter. | |||||
CVE-2021-31738 | 1 Adiscon | 1 Loganalyzer | 2021-06-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS. | |||||
CVE-2021-24342 | 1 Jnews | 1 Jnews | 2021-06-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue. | |||||
CVE-2021-34364 | 1 Refined-github Project | 1 Refined-github | 2021-06-10 | 4.3 MEDIUM | 6.1 MEDIUM |
The Refined GitHub browser extension before 21.6.8 might allow XSS via a link in a document. NOTE: github.com sends Content-Security-Policy headers to, in general, address XSS and other concerns. | |||||
CVE-2020-21003 | 1 Pbootcms | 1 Pbootcms | 2021-06-10 | 3.5 LOW | 4.8 MEDIUM |
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. | |||||
CVE-2021-30133 | 1 Cloverdx | 1 Cloverdx | 2021-06-10 | 4.3 MEDIUM | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10. | |||||
CVE-2011-3656 | 1 Mozilla | 1 Firefox | 2021-06-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing. |