Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): xss
- Search Type: Search All
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2022-42096 |
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content. Published: November 21, 2022; 4:15:11 PM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-4105 |
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page. Published: November 21, 2022; 3:15:11 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-43117 |
Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters. Published: November 21, 2022; 1:15:21 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-45470 |
** UNSUPPPORTED WHEN ASSIGNED **missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed. Published: November 21, 2022; 11:15:25 AM -0500 |
V3.1: 7.5 HIGH V2.0:(not available) |
CVE-2022-38146 |
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). Published: November 21, 2022; 11:15:13 AM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-45017 |
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field. Published: November 21, 2022; 10:15:12 AM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-45016 |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field. Published: November 21, 2022; 10:15:12 AM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-45015 |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field. Published: November 21, 2022; 10:15:12 AM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-45014 |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field. Published: November 21, 2022; 10:15:12 AM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-45013 |
A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field. Published: November 21, 2022; 10:15:11 AM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-45012 |
A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field. Published: November 21, 2022; 10:15:11 AM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-4069 |
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. Published: November 20, 2022; 12:15:12 AM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-4068 |
A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account. Published: November 20, 2022; 12:15:12 AM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-4067 |
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. Published: November 20, 2022; 12:15:11 AM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-3562 |
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. Published: November 20, 2022; 12:15:11 AM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-3561 |
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. Published: November 20, 2022; 12:15:11 AM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-3516 |
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. Published: November 20, 2022; 12:15:10 AM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-41938 |
Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a discussion title input, either by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant discussion page. All communities running Flarum from `v1.5.0` to `v1.6.1` are impacted. The vulnerability has been fixed and published as flarum/core `v1.6.2`. All communities running Flarum from `v1.5.0` to `v1.6.1` have to upgrade as soon as possible to v1.6.2. There are no known workarounds for this issue. Published: November 18, 2022; 8:15:10 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-45082 |
Multiple Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilities in Accordions plugin <= 2.0.3 on WordPress via &addons-style-name and &accordions_or_faqs_license_key. Published: November 18, 2022; 6:15:29 PM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-41788 |
Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Soledad premium theme <= 8.2.5 on WordPress. Published: November 18, 2022; 6:15:26 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |