Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32131 1 74cms 1 74cmsse 2022-06-29 4.3 MEDIUM 6.1 MEDIUM
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /index/notice/show.
CVE-2022-31373 1 Contec 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware 2022-06-29 4.3 MEDIUM 6.1 MEDIUM
SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.
CVE-2022-31303 1 Maccms 1 Maccms 2022-06-29 3.5 LOW 5.4 MEDIUM
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2022-2174 1 Microweber 1 Microweber 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
CVE-2022-23081 1 Openlibrary 1 Openlibrary 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.
CVE-2022-32159 1 Infogami 1 Infogami 2022-06-28 3.5 LOW 5.4 MEDIUM
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.
CVE-2022-31786 1 Ideaco 1 Idealms 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO.
CVE-2022-25585 1 Unioncms Project 1 Unioncms 2022-06-28 3.5 LOW 5.4 MEDIUM
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
CVE-2022-31302 1 Maccms 1 Maccms 2022-06-28 3.5 LOW 5.4 MEDIUM
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2022-23072 1 Tandoor 1 Recipes 2022-06-28 3.5 LOW 5.4 MEDIUM
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.
CVE-2022-1945 1 Colorlib 1 Coming Soon \& Maintenance Mode 2022-06-28 3.5 LOW 4.8 MEDIUM
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup)
CVE-2022-1717 1 Wp-experts 1 Custom Share Buttons With Floating Sidebar 2022-06-28 3.5 LOW 4.8 MEDIUM
The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
CVE-2022-1915 1 Wpreviewslider 1 Wp Zillow Review Slider 2022-06-28 3.5 LOW 4.8 MEDIUM
The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite)
CVE-2021-41924 1 Webkul 1 Krayin 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-23074 1 Tandoor 1 Recipes 2022-06-28 3.5 LOW 5.4 MEDIUM
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.
CVE-2022-23073 1 Tandoor 1 Recipes 2022-06-28 3.5 LOW 5.4 MEDIUM
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the clipboard icon, an XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.
CVE-2022-1896 1 Underconstruction Project 1 Underconstruction 2022-06-28 3.5 LOW 4.8 MEDIUM
The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.
CVE-2022-1889 1 Thenewsletterplugin 1 Newsletter 2022-06-28 3.5 LOW 4.8 MEDIUM
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
CVE-2022-2130 1 Microweber 1 Microweber 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.
CVE-2022-31875 1 Trendnet 2 Tv-ip110wn, Tv-ip110wn Firmware 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/scheprofile.cgi
CVE-2017-20056 1 Intechnosoftware 1 User Login Log 2022-06-28 3.5 LOW 5.4 MEDIUM
A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Stored). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2017-20055 1 Bestwebsoft 1 Contact Form 2022-06-28 3.5 LOW 5.4 MEDIUM
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.0.2 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20054 1 Xyzscripts 1 Contact Form Manager 2022-06-28 3.5 LOW 5.4 MEDIUM
A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-32442 1 Yuba 1 U5cms 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the parameter passed in is http://127.0.0.1/? "Onmouseover=%27tzgl (96502)%27bad=", it can cause html injection.
CVE-2017-20061 1 Elefantcms 1 Elefant Cms 2022-06-28 3.5 LOW 5.4 MEDIUM
A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20060 1 Elefantcms 1 Elefant Cms 2022-06-28 3.5 LOW 5.4 MEDIUM
A vulnerability, which was classified as problematic, was found in Elefant CMS 1.3.12-RC. This affects an unknown part of the component Blog Post Handler. The manipulation leads to basic cross site scripting (Persistent). It is possible to initiate the attack remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20059 1 Elefantcms 1 Elefant Cms 2022-06-28 3.5 LOW 5.4 MEDIUM
A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is some unknown functionality of the component Title Handler. The manipulation with the input </title><img src=no onerror=alert(1)> leads to basic cross site scripting (Persistent). The attack may be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20058 1 Elefantcms 1 Elefantcms 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. Affected by this vulnerability is an unknown functionality of the component Version Comparison. The manipulation leads to basic cross site scripting (Persistent). The attack can be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20057 1 Elefantcms 1 Elefant Cms 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
A vulnerability classified as problematic has been found in Elefant CMS 1.3.12-RC. Affected is an unknown function. The manipulation of the argument username leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2022-31873 1 Trendnet 2 Tv-ip110wn, Tv-ip110wn Firmware 2022-06-28 4.3 MEDIUM 6.1 MEDIUM
Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.cgi.
CVE-2022-2113 1 Inventree 1 Inventree 2022-06-27 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
CVE-2021-45026 1 Rocketsoftware 1 Ags-zena 2022-06-27 4.3 MEDIUM 6.1 MEDIUM
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-29548 1 Wso2 9 Api Manager, Api Manager Analytics, Api Microgateway and 6 more 2022-06-27 4.3 MEDIUM 6.1 MEDIUM
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.
CVE-2022-30326 1 Trendnet 2 Tew-831dr, Tew-831dr Firmware 2022-06-27 3.5 LOW 5.4 MEDIUM
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The network pre-shared key field on the web interface is vulnerable to XSS. An attacker can use a simple XSS payload to crash the basic.config page of the web interface.
CVE-2022-31299 1 Angtech 1 Haraj 2022-06-27 4.3 MEDIUM 6.1 MEDIUM
Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.
CVE-2022-31734 1 Cisco 4 Ws-c2940-8tf-s, Ws-c2940-8tf-s Firmware, Ws-c2940-8tt-s and 1 more 2022-06-27 4.3 MEDIUM 6.1 MEDIUM
** Unsupported When Assigned ** Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affected firmware is prior to 12.2(50)SY released in 2011, and Cisco Catalyst 2940 Series Switches have been retired since January 2015.
CVE-2022-25772 1 Acquia 1 Mautic 2022-06-27 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
CVE-2021-33295 1 Joplin Project 1 Joplin 2022-06-27 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.
CVE-2021-36608 1 Webtareas Project 1 Webtareas 2022-06-27 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.
CVE-2021-36609 1 Webtareas Project 1 Webtareas 2022-06-27 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.
CVE-2021-36827 1 Ninjaforms 1 Ninja Forms 2022-06-27 3.5 LOW 4.8 MEDIUM
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".
CVE-2022-31301 1 Angtech 1 Haraj 2022-06-27 3.5 LOW 5.4 MEDIUM
Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.
CVE-2021-41420 1 Maianmedia 1 Maianaffiliate 2022-06-27 3.5 LOW 5.4 MEDIUM
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.
CVE-2022-31300 1 Angtech 1 Haraj 2022-06-27 3.5 LOW 5.4 MEDIUM
A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
CVE-2022-31298 1 Angtech 1 Haraj 2022-06-27 3.5 LOW 5.4 MEDIUM
A cross-site scripting vulnerability in the ads comment section of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
CVE-2021-41663 1 1234n 1 Minicms 2022-06-27 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.
CVE-2022-29455 1 Elementor 1 Website Builder 2022-06-27 4.3 MEDIUM 6.1 MEDIUM
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
CVE-2016-1229 1 Humhub 1 Humhub 2022-06-27 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in HumHub 0.20.0-beta.1 through 0.20.1 and 1.0.0-beta before 1.0.0-beta.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2022-30533 1 Webnus 1 Modern Events Calendar Lite 2022-06-27 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2022-31906 1 Online Fire Reporting System Project 1 Online Fire Reporting System 2022-06-27 3.5 LOW 4.8 MEDIUM
Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php.