Total
34649 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-33209 | 1 Flatpress | 1 Flatpress | 2025-03-14 | N/A | 5.4 MEDIUM |
FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser. | |||||
CVE-2024-41591 | 1 Draytek | 48 Vigor1000b, Vigor1000b Firmware, Vigor165 and 45 more | 2025-03-14 | N/A | 6.1 MEDIUM |
DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS. | |||||
CVE-2024-44682 | 1 Shopxo | 1 Shopxo | 2025-03-14 | N/A | 6.1 MEDIUM |
ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters. | |||||
CVE-2024-40737 | 1 Netbox | 1 Netbox | 2025-03-14 | N/A | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-ports/add. | |||||
CVE-2024-40510 | 1 Openpetra | 1 Openpetra | 2025-03-14 | N/A | 8.2 HIGH |
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmx function. | |||||
CVE-2022-4784 | 1 Presscustomizr | 1 Hueman Addons | 2025-03-14 | N/A | 5.4 MEDIUM |
The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |||||
CVE-2024-40605 | 1 Mediawiki | 1 Mediawiki | 2025-03-14 | N/A | 4.8 MEDIUM |
An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |||||
CVE-2025-26626 | 2025-03-14 | N/A | N/A | ||
The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software package. Versions prior to 1.5.0 are vulnerable to reflective cross-site scripting, which may lead to executing javascript code. Version 1.5.0 fixes the issue. | |||||
CVE-2025-2166 | 2025-03-14 | N/A | 6.1 MEDIUM | ||
The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | |||||
CVE-2024-25973 | 1 Frentix | 1 Openolat | 2025-03-14 | N/A | 5.4 MEDIUM |
The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a name that contains an XSS payload. Furthermore, attackers with the permissions to create or rename a catalog (sub-category) can enter unfiltered input in the name field. In addition, attackers who are allowed to create curriculums can also enter unfiltered input in the name field. This allows an attacker to execute stored JavaScript code with the permissions of the victim in the context of the user's browser. | |||||
CVE-2024-4005 | 1 Labschool | 1 Social Pixel | 2025-03-13 | N/A | 4.8 MEDIUM |
The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |||||
CVE-2024-33533 | 1 Zimbra | 1 Collaboration | 2025-03-13 | N/A | 5.4 MEDIUM |
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in the Zimbra webmail admin interface. This vulnerability occurs due to inadequate input validation of the packages parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser session. By uploading a malicious JavaScript file and crafting a URL containing its location in the packages parameter, the attacker can exploit this vulnerability. Subsequently, when another user visits the crafted URL, the malicious JavaScript code is executed. | |||||
CVE-2024-45621 | 1 Rocket.chat | 1 Rocket.chat | 2025-03-13 | N/A | 5.4 MEDIUM |
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents. | |||||
CVE-2024-3800 | 1 Conceptintermedia | 1 S\@m Cms | 2025-03-13 | N/A | 6.1 MEDIUM |
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |||||
CVE-2024-41333 | 1 Phpgurukul | 1 Tourism Management System | 2025-03-13 | N/A | 6.1 MEDIUM |
A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter. | |||||
CVE-2024-41349 | 1 Cdevroe | 1 Unmark | 2025-03-13 | N/A | 6.1 MEDIUM |
unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php. | |||||
CVE-2024-29472 | 1 Zhyd | 1 Oneblog | 2025-03-13 | N/A | 5.4 MEDIUM |
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module. | |||||
CVE-2024-31847 | 1 Italtel | 1 Embrace | 2025-03-13 | N/A | 6.1 MEDIUM |
An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. This reflects/stores the user input without sanitization. | |||||
CVE-2024-25218 | 1 Task Manager In Php With Source Code Project | 1 Task Manager In Php With Source Code | 2025-03-13 | N/A | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Project Name parameter /TaskManager/Projects.php. | |||||
CVE-2024-44819 | 1 Zzcms | 1 Zzcms | 2025-03-13 | N/A | 6.1 MEDIUM |
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component. |