Total
36961 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-5473 | 1 Zitscher | 1 Simple Photoswipe | 2025-05-19 | N/A | 4.0 MEDIUM |
The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2024-3633 | 1 Rezakhan995 | 1 Webp \& Svg Support | 2025-05-19 | N/A | 5.4 MEDIUM |
The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |||||
CVE-2024-4759 | 1 Staude | 1 Mime Types Extended | 2025-05-19 | N/A | 5.5 MEDIUM |
The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |||||
CVE-2024-5730 | 1 Mahype | 1 Pagerank Tools | 2025-05-19 | N/A | 6.1 MEDIUM |
The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |||||
CVE-2024-5729 | 1 Alexdtn | 1 Simple Al Slider | 2025-05-19 | N/A | 6.1 MEDIUM |
The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |||||
CVE-2024-5728 | 1 Alexdtn | 1 Animated Al List | 2025-05-19 | N/A | 5.4 MEDIUM |
The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |||||
CVE-2024-5727 | 1 Apidaze | 1 Widget4call | 2025-05-19 | N/A | 4.7 MEDIUM |
The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |||||
CVE-2025-30316 | 1 Adobe | 1 Connect | 2025-05-19 | N/A | 5.4 MEDIUM |
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | |||||
CVE-2025-30315 | 1 Adobe | 1 Connect | 2025-05-19 | N/A | 6.1 MEDIUM |
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | |||||
CVE-2025-30314 | 1 Adobe | 1 Connect | 2025-05-19 | N/A | 6.1 MEDIUM |
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | |||||
CVE-2025-43567 | 1 Adobe | 1 Connect | 2025-05-19 | N/A | 9.3 CRITICAL |
Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. | |||||
CVE-2025-24676 | 2025-05-19 | N/A | 7.1 HIGH | ||
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in umangmetatagg Custom WP Store Locator allows Reflected XSS.This issue affects Custom WP Store Locator: from n/a through 1.4.7. | |||||
CVE-2024-6533 | 1 Monospace | 1 Directus | 2025-05-19 | N/A | 5.4 MEDIUM |
Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it could result in account takeover. | |||||
CVE-2024-2692 | 1 B3log | 1 Siyuan | 2025-05-19 | N/A | 9.0 CRITICAL |
SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS. | |||||
CVE-2023-35006 | 1 Ibm | 1 Security Qradar Edr | 2025-05-19 | N/A | 5.4 MEDIUM |
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |||||
CVE-2024-3851 | 1 Pribai | 1 Privategpt | 2025-05-19 | N/A | 5.4 MEDIUM |
A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's session when accessed. This could lead to the execution of arbitrary JavaScript code in the context of the user's browser session, potentially resulting in phishing attacks or other malicious actions. The vulnerability affects the latest version of the repository. | |||||
CVE-2023-49272 | 1 Kashipara | 1 Hotel Management | 2025-05-19 | N/A | 5.4 MEDIUM |
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. | |||||
CVE-2023-49271 | 1 Kashipara | 1 Hotel Management | 2025-05-19 | N/A | 5.4 MEDIUM |
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. | |||||
CVE-2023-49270 | 1 Kashipara | 1 Hotel Management | 2025-05-19 | N/A | 5.4 MEDIUM |
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. | |||||
CVE-2023-49269 | 1 Gvnpatidar | 1 Hotel Management System | 2025-05-19 | N/A | 5.4 MEDIUM |
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. |