Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): xss
- Search Type: Search All
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2022-38075 |
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Mantenimiento web plugin <= 0.13 on WordPress. Published: November 18, 2022; 2:15:29 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-45375 |
Auth. Stored Cross-Site Scripting (XSS) vulnerability in iFeature Slider plugin <= 1.2 on WordPress. Published: November 17, 2022; 6:15:24 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-44736 |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Chameleon plugin <= 1.4.3 on WordPress. Published: November 17, 2022; 6:15:24 PM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-44591 |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anthologize plugin <= 0.8.0 on WordPress. Published: November 17, 2022; 6:15:24 PM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-43332 |
A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel. Published: November 17, 2022; 6:15:23 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-41315 |
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Ezoic plugin <= 2.8.8 on WordPress. Published: November 17, 2022; 6:15:22 PM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-41132 |
Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress. Published: November 17, 2022; 6:15:21 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-40694 |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress. Published: November 17, 2022; 6:15:21 PM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-39181 |
GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected XSS exploits occur when an attacker causes a victim to supply dangerous content to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or emailed directly to the victim. URLs constructed in this manner constitute the core of many phishing schemes, whereby an attacker convinces a victim to visit a URL that refers to a vulnerable site. After the site reflects the attacker's content back to the victim, the content is executed by the victim's browser. Published: November 17, 2022; 6:15:19 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-36357 |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ULTIMATE TABLES plugin <= 1.6.5 on WordPress. Published: November 17, 2022; 6:15:15 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2021-36905 |
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress. Published: November 17, 2022; 6:15:11 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-43142 |
A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter. Published: November 17, 2022; 2:15:14 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-42985 |
The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS). Published: November 17, 2022; 12:15:15 AM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2022-42954 |
Keyfactor EJBCA before 7.10.0 allows XSS. Published: November 17, 2022; 12:15:15 AM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-39834 |
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user. Published: November 17, 2022; 12:15:14 AM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-42187 |
Hustoj 22.09.22 has a XSS Vulnerability in /admin/problem_judge.php. Published: November 16, 2022; 11:15:10 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-42960 |
EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DOM XSS due to improper validation of message events to accessibility.js. Published: November 16, 2022; 7:15:18 PM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-44002 |
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient output encoding of user-supplied data, the web application is vulnerable to cross-site scripting (XSS) at various locations. Published: November 16, 2022; 6:15:11 PM -0500 |
V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-44073 |
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts. Published: November 16, 2022; 11:15:11 AM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2022-44071 |
Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile. Published: November 16, 2022; 11:15:11 AM -0500 |
V3.1: 5.4 MEDIUM V2.0:(not available) |