Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24760 1 Pdf Viewer Block For Gutenberg Project 1 Pdf Viewer Block For Gutenberg 2021-10-21 3.5 LOW 5.4 MEDIUM
The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
CVE-2021-42566 1 Myfactory 1 Fms 2021-10-21 4.3 MEDIUM 6.1 MEDIUM
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
CVE-2021-42565 1 Myfactory 1 Fms 2021-10-21 4.3 MEDIUM 6.1 MEDIUM
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
CVE-2018-16061 1 Mitsubishielectric 2 Smartrtu, Smartrtu Firmware 2021-10-21 4.3 MEDIUM 6.1 MEDIUM
Mitsubishi Electric SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
CVE-2021-24672 1 Onedesigns 1 One User Avatar 2021-10-20 3.5 LOW 5.4 MEDIUM
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
CVE-2021-33988 1 Microweber 1 Microweber 2021-10-20 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
CVE-2021-42335 1 Huaju 1 Easytest Online Learning Test Platform 2021-10-20 3.5 LOW 5.4 MEDIUM
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
CVE-2021-32569 1 Ericsson 2 Operations Support System-radio And Core, Operations Support System-radio And Core Firmware 2021-10-20 4.3 MEDIUM 6.1 MEDIUM
** UNSUPPORTED WHEN ASSIGNED ** In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross-Site Scripting. This problem is completely resolved in new Ericsson library browsing tool ELEX used in systems like Ericsson Network Manager. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Ericsson Network Manager is a new generation OSS system which OSS-RC customers shall upgrade to.
CVE-2021-41139 1 Anuko 1 Time Tracker 2021-10-20 4.3 MEDIUM 6.1 MEDIUM
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects a date in Time Tracker, it is being passed on via the date parameter in URI. Because of not checking this parameter for sanity in versions prior to 1.19.30.5600, it was possible to craft the URI with malicious JavaScript, use social engineering to convince logged on user to click on such link, and have the attacker-supplied JavaScript to be executed in user's browser. This issue is patched in version 1.19.30.5600. As a workaround, one may introduce `ttValidDbDateFormatDate` function as in the latest version and add a call to it within the access checks block in time.php.
CVE-2021-41132 1 Openmicroscopy 2 Omero-figure, Omero-web 2021-10-20 4.3 MEDIUM 6.1 MEDIUM
OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site scripting possibilities with specially crafted input to a variety of fields. This issue is patched in version 5.11.0. There are no known workarounds aside from upgrading.
CVE-2021-33179 1 Nagios 1 Nagios Xi 2021-10-20 4.3 MEDIUM 6.1 MEDIUM
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
CVE-2021-41142 1 Enalean 1 Tuleap 2021-10-20 3.5 LOW 5.4 MEDIUM
Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. There is a cross-site scripting vulnerability in Tuleap Community Edition prior to 12.11.99.25 and Tuleap Enterprise Edition 12.11-2. A malicious user with the capability to add and remove attachment to an artifact could force a victim to execute uncontrolled code. Tuleap Community Edition 11.17.99.146 and Tuleap Enterprise Edition 12.11-2 contain a fix for the issue.
CVE-2021-42329 1 Xinheinformation 1 Xinhe Teaching Platform System 2021-10-20 3.5 LOW 5.4 MEDIUM
The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.
CVE-2021-39336 1 Wp-jobmanager 1 Job Manager 2021-10-20 2.1 LOW 4.8 MEDIUM
The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.7.25. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
CVE-2021-39335 1 Wpgenious 1 Wpgenius Job Listing 2021-10-20 2.1 LOW 4.8 MEDIUM
The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/admin/class/class-wpgenious-job-listing-options.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
CVE-2021-39332 1 Linksoftwarellc 1 Business Manager 2021-10-20 2.1 LOW 4.8 MEDIUM
The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization found throughout the plugin which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.4.5. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
CVE-2021-39334 1 Perceptionsystem 1 Job Board Vanila 2021-10-20 2.1 LOW 4.8 MEDIUM
The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the psjb_exp_in and the psjb_curr_in parameters found in the ~/job-settings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
CVE-2021-39344 1 Kajoom 1 Kjm Admin Notices 2021-10-20 2.1 LOW 4.8 MEDIUM
The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/class-kjm-admin-notices-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
CVE-2021-39345 1 Cnrs 1 Hal 2021-10-20 2.1 LOW 4.8 MEDIUM
The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/wp-hal.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.1.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
CVE-2021-39338 1 Mybb Cross-poster Project 1 Mybb Cross-poster 2021-10-20 2.1 LOW 4.8 MEDIUM
The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
CVE-2021-39337 1 Job-portal Project 1 Job-portal 2021-10-20 2.1 LOW 4.8 MEDIUM
The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/jobs_function.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
CVE-2021-36387 1 Yellowfinbi 1 Yellowfin 2021-10-20 3.5 LOW 5.4 MEDIUM
In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4".
CVE-2021-42227 1 Kindsoft 1 Kindeditor 2021-10-19 4.3 MEDIUM 6.1 MEDIUM
Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed).
CVE-2020-19962 1 Chaoji Cms Project 1 Chaoji Cms 2021-10-19 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.
CVE-2021-20807 1 Cybozu 1 Remote Service Manager 2021-10-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20805 1 Cybozu 1 Remote Service Manager 2021-10-19 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20800 1 Cybozu 1 Remote Service Manager 2021-10-19 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20799 1 Cybozu 1 Remote Service Manager 2021-10-19 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20798 1 Cybozu 1 Remote Service Manager 2021-10-19 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20797 1 Cybozu 1 Remote Service Manager 2021-10-19 3.5 LOW 5.4 MEDIUM
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.
CVE-2021-20128 1 Draytek 1 Vigorconnect 2021-10-19 3.5 LOW 5.4 MEDIUM
The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.
CVE-2021-40292 1 Dzzoffice 1 Dzzoffice 2021-10-19 3.5 LOW 5.4 MEDIUM
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.
CVE-2021-38183 1 Sap 1 Netweaver 2021-10-19 4.3 MEDIUM 6.1 MEDIUM
SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.
CVE-2021-42134 1 Django-unicorn 1 Unicorn 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
CVE-2021-24576 1 Techearty 1 Easy Accordion 2021-10-18 3.5 LOW 5.4 MEDIUM
The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.
CVE-2021-40191 1 Dzzoffice 1 Dzzoffice 2021-10-18 3.5 LOW 5.4 MEDIUM
Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz/attach/Uploader.class.php and return a wrong response in content-type of output data in webroot/dzz/attach/controller.php.
CVE-2021-40542 1 Os4ed 1 Opensis 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.
CVE-2021-38699 1 Tastyigniter 1 Tastyigniter 2021-10-18 3.5 LOW 5.4 MEDIUM
TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.
CVE-2021-20825 2 Ec-cube, Shiro8 2 Ec-cube, List \(order Management\) Item Change 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-40888 1 Projectsend 1 Projectsend 2021-10-18 3.5 LOW 5.4 MEDIUM
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code.
CVE-2021-24275 1 Supsystic 1 Popup 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
CVE-2021-24274 1 Supsystic 1 Ultimate Maps 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
CVE-2021-24286 1 Mooveagency 1 Redirect 404 To Parent 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
CVE-2021-24276 1 Supsystic 1 Contact Form 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
CVE-2021-24176 1 Jh 404 Logger Project 1 Jh 404 Logger 2021-10-18 3.5 LOW 5.4 MEDIUM
The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.
CVE-2019-12823 1 Craftcms 1 Craft Cms 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
CVE-2018-7543 1 Snapcreek 1 Duplicator 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.
CVE-2021-24678 1 Cminds 1 Tooltip Glossary 2021-10-18 3.5 LOW 5.4 MEDIUM
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks
CVE-2021-34370 1 Accela 1 Civic Platform 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information."
CVE-2021-33904 1 Accela 1 Civic Platform 2021-10-18 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information."