U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): xss
  • Search Type: Search All
There are 21,175 matching records.
Displaying matches 801 through 820.
Vuln ID Summary CVSS Severity
CVE-2022-38075

Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Mantenimiento web plugin <= 0.13 on WordPress.

Published: November 18, 2022; 2:15:29 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-45375

Auth. Stored Cross-Site Scripting (XSS) vulnerability in iFeature Slider plugin <= 1.2 on WordPress.

Published: November 17, 2022; 6:15:24 PM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-44736

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Chameleon plugin <= 1.4.3 on WordPress.

Published: November 17, 2022; 6:15:24 PM -0500
V3.1: 4.8 MEDIUM
V2.0:(not available)
CVE-2022-44591

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anthologize plugin <= 0.8.0 on WordPress.

Published: November 17, 2022; 6:15:24 PM -0500
V3.1: 4.8 MEDIUM
V2.0:(not available)
CVE-2022-43332

A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel.

Published: November 17, 2022; 6:15:23 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-41315

Auth. Stored Cross-Site Scripting (XSS) vulnerability in Ezoic plugin <= 2.8.8 on WordPress.

Published: November 17, 2022; 6:15:22 PM -0500
V3.1: 4.8 MEDIUM
V2.0:(not available)
CVE-2022-41132

Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.

Published: November 17, 2022; 6:15:21 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-40694

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.

Published: November 17, 2022; 6:15:21 PM -0500
V3.1: 4.8 MEDIUM
V2.0:(not available)
CVE-2022-39181

GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected XSS exploits occur when an attacker causes a victim to supply dangerous content to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or emailed directly to the victim. URLs constructed in this manner constitute the core of many phishing schemes, whereby an attacker convinces a victim to visit a URL that refers to a vulnerable site. After the site reflects the attacker's content back to the victim, the content is executed by the victim's browser.

Published: November 17, 2022; 6:15:19 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-36357

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ULTIMATE TABLES plugin <= 1.6.5 on WordPress.

Published: November 17, 2022; 6:15:15 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2021-36905

Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.

Published: November 17, 2022; 6:15:11 PM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-43142

A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.

Published: November 17, 2022; 2:15:14 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-42985

The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).

Published: November 17, 2022; 12:15:15 AM -0500
V3.1: 4.8 MEDIUM
V2.0:(not available)
CVE-2022-42954

Keyfactor EJBCA before 7.10.0 allows XSS.

Published: November 17, 2022; 12:15:15 AM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-39834

A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.

Published: November 17, 2022; 12:15:14 AM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-42187

Hustoj 22.09.22 has a XSS Vulnerability in /admin/problem_judge.php.

Published: November 16, 2022; 11:15:10 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-42960

EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DOM XSS due to improper validation of message events to accessibility.js.

Published: November 16, 2022; 7:15:18 PM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-44002

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient output encoding of user-supplied data, the web application is vulnerable to cross-site scripting (XSS) at various locations.

Published: November 16, 2022; 6:15:11 PM -0500
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2022-44073

Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.

Published: November 16, 2022; 11:15:11 AM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-44071

Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.

Published: November 16, 2022; 11:15:11 AM -0500
V3.1: 5.4 MEDIUM
V2.0:(not available)