Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): xss
- Search Type: Search All
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2022-4307 |
The ?????? ?????? ?????? WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenticated attackers to send a request with XSS payloads, which will be triggered when a high privilege users such as admin visits a page from the plugin. Published: January 23, 2023; 10:15:14 AM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2021-43446 |
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used. Published: January 23, 2023; 10:15:13 AM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-24070 |
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field. Published: January 23, 2023; 12:15:18 AM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-24027 |
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name. Published: January 20, 2023; 5:15:10 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-24026 |
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload. Published: January 20, 2023; 5:15:10 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-23024 |
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the writer parameter. Published: January 20, 2023; 2:15:18 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-23015 |
Cross Site Scripting (XSS) vulnerability in Kalkun 0.8.0 via username input in file User_model.php. Published: January 20, 2023; 2:15:18 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-23014 |
Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php. Published: January 20, 2023; 2:15:18 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-23012 |
Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file Weeks.php. Published: January 20, 2023; 2:15:18 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-23010 |
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php. Published: January 20, 2023; 2:15:18 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-45558 |
Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via the meta tag. Published: January 20, 2023; 2:15:16 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-45557 |
Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via file names. Published: January 20, 2023; 2:15:16 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-45542 |
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file. Published: January 20, 2023; 2:15:16 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-45541 |
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char. Published: January 20, 2023; 2:15:16 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-45540 |
EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char. Published: January 20, 2023; 2:15:16 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-45539 |
EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file. Published: January 20, 2023; 2:15:16 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-45538 |
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL". Published: January 20, 2023; 2:15:16 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-45537 |
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL". Published: January 20, 2023; 2:15:16 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-22910 |
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision-* fields. This allows JavaScript execution by staff/admin users who do not intentionally have the editsitejs capability. Published: January 20, 2023; 1:15:10 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-41441 |
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters. Published: January 20, 2023; 10:15:13 AM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |