Total
35685 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-19918 | 1 Cuppacms | 1 Cuppacms | 2025-05-06 | 5.4 Medium |
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI. | ||||
CVE-2018-19906 | 1 Razorcms | 1 Razorcms | 2025-05-06 | 5.4 Medium |
Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter. | ||||
CVE-2018-19905 | 1 Razorcms | 1 Razorcms | 2025-05-06 | 5.4 Medium |
HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. | ||||
CVE-2024-12683 | 1 Brijeshk89 | 1 Smart Maintenance Mode | 2025-05-06 | 3.5 Low |
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
CVE-2023-41708 | 1 Open-xchange | 1 Open-xchange Appsuite | 2025-05-06 | 5.4 Medium |
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known. | ||||
CVE-2023-51458 | 1 Adobe | 1 Experience Manager | 2025-05-06 | 5.4 Medium |
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | ||||
CVE-2024-44046 | 1 Themify | 1 Woocommerce Product Filter | 2025-05-06 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify – WooCommerce Product Filter allows Stored XSS.This issue affects Themify – WooCommerce Product Filter: from n/a through 1.5.1. | ||||
CVE-2024-5968 | 1 10web | 1 Photo Gallery | 2025-05-06 | 4.8 Medium |
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
CVE-2025-25062 | 2025-05-06 | 4.4 Medium | ||
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attacker must have the ability to create long text content (such as through the node or comment forms) and an administrator must edit (not view) the content that contains the malicious content. This problem only exists when using the CKEditor 5 module. | ||||
CVE-2024-48622 | 1 Domainmod | 1 Domainmod | 2025-05-06 | 6.6 Medium |
A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter. | ||||
CVE-2024-48623 | 1 Domainmod | 1 Domainmod | 2025-05-06 | 5.3 Medium |
In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS). | ||||
CVE-2024-48624 | 1 Domainmod | 1 Domainmod | 2025-05-06 | 5.3 Medium |
In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability. | ||||
CVE-2024-25381 | 1 Emlog | 1 Emlog | 2025-05-06 | 6.1 Medium |
There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content. | ||||
CVE-2022-40487 | 1 Processwire | 1 Processwire | 2025-05-06 | 6.1 Medium |
ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload. | ||||
CVE-2018-6341 | 1 Facebook | 1 React | 2025-05-06 | 6.1 Medium |
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2. | ||||
CVE-2024-5075 | 1 Tipsandtricks-hq | 1 Wp Emember | 2025-05-06 | 5.9 Medium |
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | ||||
CVE-2025-25001 | 2025-05-06 | 4.3 Medium | ||
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||||
CVE-2024-5079 | 1 Tipsandtricks-hq | 1 Wp Emember | 2025-05-06 | 6.1 Medium |
The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks | ||||
CVE-2024-40576 | 2 Mayurik, Sourcecodester | 2 Best House Rental Management System, Best House Rental Management System | 2025-05-06 | 4.7 Medium |
Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" parameters in the houses page at the index.php component. | ||||
CVE-2024-6408 | 1 10web | 1 Slider | 2025-05-06 | 5.4 Medium |
The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed |