U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): xss
  • Search Type: Search All
There are 21,124 matching records.
Displaying matches 21 through 40.
Vuln ID Summary CVSS Severity
CVE-2023-25782

Auth. (admin+) vulnerability in Second2none Service Area Postcode Checker plugin <= 2.0.8 versions.

Published: March 20, 2023; 6:15:11 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-1248

Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7.0.42; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

Published: March 20, 2023; 5:15:11 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-1496

Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.

Published: March 19, 2023; 1:15:11 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-1485

A vulnerability classified as problematic has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. This affects an unknown part of the file /bsenordering/index.php of the component GET Parameter Handler. The manipulation of the argument category with the input <script>alert(222)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223371.

Published: March 18, 2023; 5:15:11 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-28607

js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.

Published: March 18, 2023; 2:15:54 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-28606

js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.

Published: March 18, 2023; 2:15:54 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-1481

A vulnerability, which was classified as problematic, has been found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this issue is some unknown functionality of the file modules/balance/index.php?view=balancelist of the component POST Parameter Handler. The manipulation of the argument id with the input "><script>alert(111)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223364.

Published: March 18, 2023; 5:15:11 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-24278

Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.

Published: March 18, 2023; 12:16:02 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-45817

Cross-Site Scripting (XSS) vulnerability in Erin Garscadden GC Testimonials plugin <= 1.3.2 versions.

Published: March 17, 2023; 10:15:12 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-45814

Stored Cross-Site Scripting (XSS) vulnerability in Fabian von Allmen WP Calendar plugin <= 1.5.3 versions.

Published: March 17, 2023; 10:15:12 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-43461

Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.

Published: March 17, 2023; 10:15:11 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-27059

A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Group Name text field.

Published: March 16, 2023; 6:15:11 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-27494

Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with Javascript payloads to a Streamlit app. The attacker could then trick the user into visiting the malicious URL and, if successful, the server would render the malicious javascript payload as-is, leading to XSS. Version 0.81.0 contains a patch for this vulnerability.

Published: March 16, 2023; 5:15:13 PM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-27711

Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component.

Published: March 16, 2023; 11:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2021-36821

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in WPMU DEV Forminator – Contact Form, Payment Form & Custom Form Builder plugin <= 1.14.11 versions.

Published: March 16, 2023; 11:15:10 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-1429

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.

Published: March 16, 2023; 8:15:11 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2022-41554

Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.

Published: March 16, 2023; 6:15:09 AM -0400
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-40699

Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions.

Published: March 16, 2023; 5:15:09 AM -0400
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-38971

Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.

Published: March 16, 2023; 5:15:09 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-26951

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module.

Published: March 15, 2023; 9:15:46 PM -0400
V3.1: 5.4 MEDIUM
V2.0:(not available)