Search Results (45592 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-23687 1 Youtube Shortcode Project 1 Youtube Shortcode 2025-01-13 6.5 Medium
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions.
CVE-2022-29416 1 Afterpay 1 Afterpay Gateway For Woocommerce 2025-01-13 4.7 Medium
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.
CVE-2022-37402 1 Afsanalytics 1 Afs Analytics 2025-01-13 4.8 Medium
Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions.
CVE-2022-38971 1 Themekraft 1 Post Form Registration Form Profile Form For User Profiles And Content Forms 2025-01-13 4.7 Medium
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
CVE-2022-40699 1 Yasr - Yet Another Stars Rating Project 1 Yasr - Yet Another Stars Rating 2025-01-13 5.4 Medium
Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions.
CVE-2022-41554 1 Slideshow Se Project 1 Slideshow Se 2025-01-13 4.8 Medium
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
CVE-2022-43461 1 Slideshow Se Project 1 Slideshow Se 2025-01-13 4.8 Medium
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
CVE-2022-45817 1 Gc Testimonials Project 1 Gc Testimonials 2025-01-13 5.4 Medium
Cross-Site Scripting (XSS) vulnerability in Erin Garscadden GC Testimonials plugin <= 1.3.2 versions.
CVE-2023-25795 1 Wp-master 1 Feed Changer \& Remover 2025-01-13 5.9 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions.
CVE-2023-25794 1 Nooz Project 1 Nooz 2025-01-13 5.9 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0 versions.
CVE-2024-13141 1 Osuuu 1 Lightpicture 2025-01-10 3.5 Low
A vulnerability classified as problematic was found in osuuu LightPicture up to 1.2.2. This vulnerability affects unknown code of the file /api/upload of the component SVG File Upload Handler. The manipulation of the argument file leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12846 1 Emlog 1 Emlog 2025-01-10 4.3 Medium
A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is some unknown functionality of the file /admin/link.php. The manipulation of the argument siteurl/icon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-13140 1 Emlog 1 Emlog 2025-01-10 3.5 Low
A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.3. Affected is an unknown function of the file /admin/article.php?action=upload_cover of the component Cover Upload Handler. The manipulation of the argument image leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12783 1 Angeljudesuarez 1 Vehicle Management System 2025-01-10 3.5 Low
A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /billaction.php. The manipulation of the argument extra-cost leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12883 1 Anisha 1 Job Recruitment 2025-01-10 4.3 Medium
A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /_email.php. The manipulation of the argument email leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-13137 1 Wangl1989 1 Mysiteforme 2025-01-10 2.4 Low
A vulnerability was found in wangl1989 mysiteforme 1.0. It has been classified as problematic. This affects the function RestResponse of the file src/main/java/com/mysiteforme/admin/controller/system/SiteController. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-32685 1 Kanboard 1 Kanboard 2025-01-10 4.4 Medium
Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable Kanboard instance can trick the victim into pasting malicious screenshot data and achieve cross-site scripting if CSP is improperly configured. This issue has been patched in version 1.2.29.
CVE-2023-33186 1 Zulip 1 Zulip Server 2025-01-10 8.2 High
Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, including beta versions 7.0-beta1 and 7.0-beta2, is vulnerable to a cross-site scripting vulnerability in tooltips on the message feed. An attacker who can send messages could maliciously craft a topic for the message, such that a victim who hovers the tooltip for that topic in their message feed triggers execution of JavaScript code controlled by the attacker.
CVE-2025-0228 1 Code-projects 1 Local Storage Todo App 2025-01-10 2.4 Low
A vulnerability has been found in code-projects Local Storage Todo App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /js-todo-app/index.html. The manipulation of the argument Add leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-41752 1 Ibm 1 Cognos Analytics 2025-01-10 5.4 Medium
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.