Export limit exceeded: 347031 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (45628 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-1627 1 Qodeinteractive 1 Qi Blocks 2026-01-09 5.4 Medium
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2025-1626 1 Qodeinteractive 1 Qi Blocks 2026-01-09 5.4 Medium
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2025-1625 1 Qodeinteractive 1 Qi Blocks 2026-01-09 5.4 Medium
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2025-1382 1 Lordlinus 1 Contact Us 2026-01-09 6.1 Medium
The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-9458 1 Reservit 1 Reservit Hotel 2026-01-09 4.8 Medium
The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-13669 1 Margiov 1 Calendapp 2026-01-09 6.1 Medium
The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13352 1 Alwayscurious 1 Legull 2026-01-09 7.1 High
The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13219 1 Waelhassan 1 Privacy Policy Genius 2026-01-09 6.1 Medium
The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-10710 2 Antongorodezkiy, Yadisk Files 2 Yadisk Files, Yadisk Files 2026-01-09 3.5 Low
The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-5971 1 Pdfcrowd 1 Save As Pdf 2026-01-09 4.8 Medium
The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-0239 1 Ari-soft 1 Contact Form 7 Connector 2026-01-09 6.1 Medium
The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.
CVE-2023-0094 1 Qoders 1 Upqode Google Maps 2026-01-09 5.4 Medium
The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2022-23179 1 Themehunk 1 Contact Form \& Lead Form Elementor Builder 2026-01-09 4.8 Medium
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2024-11846 1 Goodlayers 1 Travel Tour 2026-01-09 6.1 Medium
The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-37471 1 Xtendify 1 Woffice 2026-01-09 7.1 High
Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.
CVE-2024-43184 1 Ibm 1 Jazz Foundation 2026-01-09 6.1 Medium
IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2025-63735 2 Ruckus, Ruckuswireless 2 Unleashed, Ruckus Unleashed 2026-01-09 6.1 Medium
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
CVE-2025-64054 1 Fanvil 3 X210, X210 Firmware, X210 V2 2026-01-09 9.6 Critical
A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.
CVE-2023-3193 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-01-09 6.1 Medium
Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
CVE-2023-33937 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-01-09 5.4 Medium
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field.