Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): xss
- Search Type: Search All
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2023-25782 |
Auth. (admin+) vulnerability in Second2none Service Area Postcode Checker plugin <= 2.0.8 versions. Published: March 20, 2023; 6:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-1248 |
Improper Input Validation vulnerability in OTRS AG OTRS (Ticket Actions modules), OTRS AG ((OTRS)) Community Edition (Ticket Actions modules) allows Cross-Site Scripting (XSS).This issue affects OTRS: from 7.0.X before 7.0.42; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34. Published: March 20, 2023; 5:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-1496 |
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0. Published: March 19, 2023; 1:15:11 PM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-1485 |
A vulnerability classified as problematic has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. This affects an unknown part of the file /bsenordering/index.php of the component GET Parameter Handler. The manipulation of the argument category with the input <script>alert(222)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223371. Published: March 18, 2023; 5:15:11 PM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-28607 |
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip. Published: March 18, 2023; 2:15:54 PM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-28606 |
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips. Published: March 18, 2023; 2:15:54 PM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-1481 |
A vulnerability, which was classified as problematic, has been found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this issue is some unknown functionality of the file modules/balance/index.php?view=balancelist of the component POST Parameter Handler. The manipulation of the argument id with the input "><script>alert(111)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223364. Published: March 18, 2023; 5:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-24278 |
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability. Published: March 18, 2023; 12:16:02 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2022-45817 |
Cross-Site Scripting (XSS) vulnerability in Erin Garscadden GC Testimonials plugin <= 1.3.2 versions. Published: March 17, 2023; 10:15:12 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2022-45814 |
Stored Cross-Site Scripting (XSS) vulnerability in Fabian von Allmen WP Calendar plugin <= 1.5.3 versions. Published: March 17, 2023; 10:15:12 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2022-43461 |
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions. Published: March 17, 2023; 10:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-27059 |
A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Group Name text field. Published: March 16, 2023; 6:15:11 PM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-27494 |
Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with Javascript payloads to a Streamlit app. The attacker could then trick the user into visiting the malicious URL and, if successful, the server would render the malicious javascript payload as-is, leading to XSS. Version 0.81.0 contains a patch for this vulnerability. Published: March 16, 2023; 5:15:13 PM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-27711 |
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component. Published: March 16, 2023; 11:15:10 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2021-36821 |
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in WPMU DEV Forminator – Contact Form, Payment Form & Custom Form Builder plugin <= 1.14.11 versions. Published: March 16, 2023; 11:15:10 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-1429 |
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19. Published: March 16, 2023; 8:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2022-41554 |
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions. Published: March 16, 2023; 6:15:09 AM -0400 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-40699 |
Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions. Published: March 16, 2023; 5:15:09 AM -0400 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-38971 |
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. Published: March 16, 2023; 5:15:09 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2023-26951 |
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module. Published: March 15, 2023; 9:15:46 PM -0400 |
V3.1: 5.4 MEDIUM V2.0:(not available) |