U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): xss
  • Search Type: Search All
There are 21,220 matching records.
Displaying matches 461 through 480.
Vuln ID Summary CVSS Severity
CVE-2022-4307

The ?????? ?????? ?????? WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenticated attackers to send a request with XSS payloads, which will be triggered when a high privilege users such as admin visits a page from the plugin.

Published: January 23, 2023; 10:15:14 AM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2021-43446

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.

Published: January 23, 2023; 10:15:13 AM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-24070

app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.

Published: January 23, 2023; 12:15:18 AM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-24027

In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.

Published: January 20, 2023; 5:15:10 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-24026

In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.

Published: January 20, 2023; 5:15:10 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-23024

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the writer parameter.

Published: January 20, 2023; 2:15:18 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-23015

Cross Site Scripting (XSS) vulnerability in Kalkun 0.8.0 via username input in file User_model.php.

Published: January 20, 2023; 2:15:18 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-23014

Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php.

Published: January 20, 2023; 2:15:18 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-23012

Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file Weeks.php.

Published: January 20, 2023; 2:15:18 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-23010

Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.

Published: January 20, 2023; 2:15:18 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-45558

Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via the meta tag.

Published: January 20, 2023; 2:15:16 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-45557

Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via file names.

Published: January 20, 2023; 2:15:16 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-45542

EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.

Published: January 20, 2023; 2:15:16 PM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-45541

EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char.

Published: January 20, 2023; 2:15:16 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-45540

EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char.

Published: January 20, 2023; 2:15:16 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-45539

EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file.

Published: January 20, 2023; 2:15:16 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-45538

EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".

Published: January 20, 2023; 2:15:16 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-45537

EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".

Published: January 20, 2023; 2:15:16 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-22910

An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision-* fields. This allows JavaScript execution by staff/admin users who do not intentionally have the editsitejs capability.

Published: January 20, 2023; 1:15:10 PM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-41441

Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.

Published: January 20, 2023; 10:15:13 AM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)