Filtered by vendor
Subscriptions
Total
45049 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-1026 | 1 Cogites | 1 Ereserv | 2025-06-09 | 3.5 Low |
| A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. This issue affects some unknown processing of the file front/admin/config.php. The manipulation of the argument id with the input %22%3E%3Cscript%3Ealert(%27XSS%27)%3C/script%3E leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-252293 was assigned to this vulnerability. | ||||
| CVE-2023-41178 | 1 Trendmicro | 1 Mobile Security | 2025-06-09 | 6.1 Medium |
| Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to, but not identical to, CVE-2023-41176. | ||||
| CVE-2024-43125 | 1 Dotcamp | 1 Wp Table Builder | 2025-06-09 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Table Builder WP Table Builder – WordPress Table Plugin allows Stored XSS.This issue affects WP Table Builder – WordPress Table Plugin: from n/a through 1.4.15. | ||||
| CVE-2025-4429 | 1 Gearside | 1 Gearside Developer Dashboard | 2025-06-09 | 6.1 Medium |
| The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | ||||
| CVE-2024-35765 | 1 Wpsoul | 1 Greenshift | 2025-06-09 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Stored XSS.This issue affects Greenshift – animation and page builder blocks: from n/a through 8.8.9.1. | ||||
| CVE-2025-4133 | 1 Adenion | 1 Blog2social | 2025-06-09 | 5.4 Medium |
| The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashboard, which could allow users with the contributor role to perform Cross-Site Scripting attacks. | ||||
| CVE-2024-6798 | 1 Dyadyalesha | 1 Dl Verification | 2025-06-09 | 4.8 Medium |
| The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-13053 | 1 10web | 1 Form Maker | 2025-06-09 | 4.8 Medium |
| The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-12874 | 1 Top Comments Project | 1 Top Comments | 2025-06-09 | 4.8 Medium |
| The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-12873 | 1 F1logic | 1 Custom Field Manager | 2025-06-09 | 6.1 Medium |
| The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | ||||
| CVE-2024-0589 | 2 Devolutions, Microsoft | 2 Remote Desktop Manager, Windows | 2025-06-09 | 5.4 Medium |
| Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry. | ||||
| CVE-2024-48704 | 1 Phpgurukul | 1 Medical Card Generation System | 2025-06-09 | 6.1 Medium |
| Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes. | ||||
| CVE-2025-5383 | 1 Wanglongcn | 1 Yifang | 2025-06-09 | 2.4 Low |
| A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Article Management Module. The manipulation of the argument Default Value leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-31501 | 1 Bestpractical | 1 Request Tracker | 2025-06-09 | 7.2 High |
| Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. | ||||
| CVE-2025-31500 | 1 Bestpractical | 1 Request Tracker | 2025-06-09 | 7.2 High |
| Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. | ||||
| CVE-2023-7168 | 1 Antonpug | 1 Better Flow Button For Jetpack | 2025-06-09 | 4.8 Medium |
| The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-11189 | 1 Reputeinfosystems | 1 Social Share And Social Locker | 2025-06-09 | 4.8 Medium |
| The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-11502 | 1 Wpchurchteam | 1 Planning Center Online Giving | 2025-06-09 | 5.4 Medium |
| The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2024-11718 | 1 Couleurcitron | 1 Tarteaucitron-wp | 2025-06-09 | 5.4 Medium |
| The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2024-11843 | 1 Projectpanorama | 1 Panorama | 2025-06-09 | 4.8 Medium |
| The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
ReportizFlow