Export limit exceeded: 46124 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (46124 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-39346 | 1 Supsystic | 1 Easy Google Maps | 2025-03-31 | 4.8 Medium |
| The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. | ||||
| CVE-2021-38356 | 1 Nextscripts | 1 Social Networks Auto Poster | 2025-03-31 | 6.1 Medium |
| The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript in $_POST['page']. | ||||
| CVE-2021-39340 | 1 Bracketspace | 1 Notification | 2025-03-31 | 4.8 Medium |
| The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 7.2.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. | ||||
| CVE-2023-0470 | 1 Modoboa | 1 Modoboa | 2025-03-31 | 5.4 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4. | ||||
| CVE-2023-0488 | 2 Pyload, Pyload-ng Project | 2 Pyload, Pyload-ng | 2025-03-31 | 5.4 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42. | ||||
| CVE-2024-43292 | 1 Envothemes | 1 Envo\'s Elementor Templates \& Widgets For Woocommerce | 2025-03-31 | 5.9 Medium |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates & Widgets for WooCommerce: from n/a through 1.4.16. | ||||
| CVE-2023-0519 | 1 Modoboa | 1 Modoboa | 2025-03-31 | 5.4 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4. | ||||
| CVE-2013-0202 | 1 Owncloud | 1 Owncloud Server | 2025-03-31 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php. | ||||
| CVE-2013-0203 | 1 Owncloud | 2 Owncloud, Owncloud Server | 2025-03-31 | 5.4 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/ajax/addBookmark.php. | ||||
| CVE-2024-21724 | 1 Joomla | 1 Joomla\! | 2025-03-29 | 6.1 Medium |
| Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions. | ||||
| CVE-2024-25865 | 1 Anzhiyu-c | 1 Hexo-theme-anzhiyu | 2025-03-29 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function. | ||||
| CVE-2024-25435 | 1 Md1health | 1 Md1patient | 2025-03-29 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter. | ||||
| CVE-2024-23349 | 1 Apache | 1 Answer | 2025-03-28 | 5.4 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack. Users are recommended to upgrade to version [1.2.5], which fixes the issue. | ||||
| CVE-2024-22344 | 1 Ibm | 2 Txseries For Multiplatform, Txseries For Multiplatforms | 2025-03-28 | 6.1 Medium |
| IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 280191. | ||||
| CVE-2024-11993 | 1 Liferay | 2 Digital Experience Platform, Liferay Portal | 2025-03-28 | 6.1 Medium |
| Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field | ||||
| CVE-2024-0820 | 1 Blueglass | 1 Jobs For Wordpress | 2025-03-28 | 5.4 Medium |
| The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2022-44024 | 1 Netscout | 1 Ngeniusone | 2025-03-28 | 6.1 Medium |
| An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 1 of 6. | ||||
| CVE-2022-39813 | 1 Italtel | 1 Netmatch-s Ci | 2025-03-28 | 6.1 Medium |
| Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via the j_username parameter, or NMSCIWebGui/actloglineview.jsp via the name or actLine parameter. An attacker leveraging this vulnerability could inject arbitrary JavaScript. The payload would then be triggered every time an authenticated user browses the page containing it. | ||||
| CVE-2024-57686 | 1 Phpgurukul | 1 Land Record System | 2025-03-28 | 9.8 Critical |
| A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter. | ||||
| CVE-2024-34089 | 2 Archer, Archerirm | 2 Platform, Archer | 2025-03-28 | 7.3 High |
| An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 P3 (6.14.0.3) is also a fixed release. | ||||