Export limit exceeded: 45966 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (45966 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-5409 | 1 Saltos | 1 Rhinos | 2025-06-05 | 7.1 High |
| RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details. | ||||
| CVE-2024-5408 | 1 Saltos | 1 Rhinos | 2025-06-05 | 7.1 High |
| Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a specially crafted URL. | ||||
| CVE-2025-3649 | 1 Lightpress | 1 Lightbox | 2025-06-05 | 6.8 Medium |
| The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks. | ||||
| CVE-2024-13384 | 1 Robosoft | 1 Robo Gallery | 2025-06-05 | 4.8 Medium |
| The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-2869 | 1 Realestateconnected | 1 Easy Property Listings | 2025-06-05 | 4.8 Medium |
| The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2024-6665 | 1 Optimalaccess | 1 Kbucket | 2025-06-05 | 4.8 Medium |
| The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2024-6667 | 1 Optimalaccess | 1 Kbucket | 2025-06-05 | 6.1 Medium |
| The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin. | ||||
| CVE-2024-9227 | 1 Blubrry | 1 Powerpress | 2025-06-05 | 4.8 Medium |
| The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | ||||
| CVE-2025-45387 | 1 Osticket | 1 Osticket | 2025-06-05 | 5.4 Medium |
| osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php. | ||||
| CVE-2025-3584 | 1 Thenewsletterplugin | 1 Newsletter | 2025-06-05 | 4.8 Medium |
| The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2023-4406 | 1 Kc Group E-commerce Software Project | 1 Kc Group E-commerce Software | 2025-06-05 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KC Group E-Commerce Software allows Reflected XSS.This issue affects E-Commerce Software: through 20231123. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2025-3662 | 1 Colorlib | 1 Fancybox | 2025-06-05 | 6.1 Medium |
| The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS | ||||
| CVE-2024-39031 | 1 Silverpeas | 1 Silverpeas | 2025-06-05 | 5.4 Medium |
| In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and then add the administrator or any user to the event. When the invited user (victim) views their own profile, the payload will be executed on their side, even if they do not click on the event. | ||||
| CVE-2023-5942 | 2 Drelton, Medialist | 2 Medialist, Medialist | 2025-06-05 | 5.4 Medium |
| The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2023-2707 | 1 Gappointments | 1 Gappointments | 2025-06-05 | 4.8 Medium |
| The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2023-44383 | 1 Octobercms | 1 October | 2025-06-05 | 5.4 Medium |
| October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported. This issue has been patched in version 3.5.2. | ||||
| CVE-2024-22725 | 1 Orthanc-server | 1 Orthanc | 2025-06-04 | 6.1 Medium |
| Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting. | ||||
| CVE-2024-27186 | 1 Joomla | 1 Joomla\! | 2025-06-04 | 6.1 Medium |
| The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | ||||
| CVE-2024-40743 | 1 Joomla | 1 Joomla\! | 2025-06-04 | 6.1 Medium |
| The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors. | ||||
| CVE-2024-40745 | 1 Convert Forms Project | 1 Convert Forms | 2025-06-04 | 5.4 Medium |
| Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8. | ||||