Total
38109 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-41505 | 2025-06-12 | N/A | 6.1 MEDIUM | ||
Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section via the field "Profisso" (professor). | |||||
CVE-2024-41502 | 2025-06-12 | N/A | 6.1 MEDIUM | ||
Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (observances) in the "Pessoas" (persons) section when creating or editing either a legal or a natural person. | |||||
CVE-2024-41504 | 2025-06-12 | N/A | 6.1 MEDIUM | ||
Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript. | |||||
CVE-2025-4666 | 2025-06-12 | N/A | 6.4 MEDIUM | ||
The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versions up to, and including, 7.3.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
CVE-2025-49185 | 2025-06-12 | N/A | 5.5 MEDIUM | ||
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source. | |||||
CVE-2025-32465 | 2025-06-12 | N/A | N/A | ||
A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload. | |||||
CVE-2025-3302 | 2025-06-12 | N/A | 7.2 HIGH | ||
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.1.0.0. | |||||
CVE-2024-8701 | 1 Snumb130 | 1 Events Calendar | 2025-06-12 | N/A | 4.8 MEDIUM |
The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2024-8492 | 1 Wpmudev | 1 Hustle | 2025-06-12 | N/A | 4.8 MEDIUM |
The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |||||
CVE-2024-8397 | 1 Webtoffee | 1 Gdpr Cookie Consent | 2025-06-12 | N/A | 5.4 MEDIUM |
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context. | |||||
CVE-2024-8284 | 1 W3eden | 1 Download Manager | 2025-06-12 | N/A | 4.8 MEDIUM |
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |||||
CVE-2024-11266 | 1 Pixeljar | 1 Geocache Stat Bar Widget | 2025-06-12 | N/A | 4.8 MEDIUM |
The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2024-24062 | 1 Aitangbao | 1 Springboot-manager | 2025-06-12 | N/A | 5.4 MEDIUM |
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role. | |||||
CVE-2024-24060 | 1 Aitangbao | 1 Springboot-manager | 2025-06-12 | N/A | 5.4 MEDIUM |
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user. | |||||
CVE-2023-5758 | 1 Mozilla | 1 Firefox | 2025-06-12 | N/A | 6.1 MEDIUM |
When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119. | |||||
CVE-2024-11221 | 1 Mohsinrasool | 1 Full Screen \(page\) Background Image Slideshow | 2025-06-12 | N/A | 4.8 MEDIUM |
The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2024-11190 | 1 Jidaikobo | 1 Jwp-a11y | 2025-06-12 | N/A | 4.8 MEDIUM |
The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2024-11141 | 1 Jontasc | 1 Sailthru Triggermail | 2025-06-12 | N/A | 6.1 MEDIUM |
The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2024-10818 | 1 Wvega | 1 Jsfiddle Shortcode | 2025-06-12 | N/A | 5.4 MEDIUM |
The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2024-10639 | 1 Klarned | 1 Auto Prune Posts | 2025-06-12 | N/A | 4.8 MEDIUM |
The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |