Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-46822 | 1 Visser | 1 Store Exporter For Woocommerce | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Unauth. Reflected Cross-Site Scripting') vulnerability in Visser Labs Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin <= 2.7.2 versions.
|
|||||
| CVE-2023-46783 | 1 Brightplugins | 1 Pre-orders For Woocommerce | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bright Plugins Pre-Orders for WooCommerce plugin <= 1.2.13 versions.
|
|||||
| CVE-2023-46782 | 1 Chrisyee | 1 Momentopress For Momento360 | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Yee MomentoPress for Momento360 plugin <= 1.0.1 versions.
|
|||||
| CVE-2023-46744 | 1 Squidex.io | 1 Squidex | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering mechanism intended to stop XSS attacks through uploaded SVG images, is insufficient resulting to stored XSS attacks. Squidex allows the CMS contributors to be granted the permission of uploading an SVG asset. When the asset is uploaded, a filtering mechanism is performed to validate ...
Show More |
|||||
| CVE-2023-46735 | 1 Sensiolabs | 1 Symfony | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input in its response.
|
|||||
| CVE-2023-46734 | 1 Sensiolabs | 2 Symfony, Twig | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.
|
|||||
| CVE-2023-46732 | 1 Xwiki | 1 Xwiki | 2024-11-21 | N/A | 9.6 CRITICAL |
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to reflected cross-site scripting (RXSS) via the `rev` parameter that is used in the content of the content menu without escaping. If an attacker can convince a user to visit a link with a crafted parameter, this allows the attacker to execute arbitrary actions in the name of the user, including remote code (Groovy) execution in the case of a user with programming right, c ...
Show More |
|||||
| CVE-2023-46722 | 1 Pimcore | 1 Admin Classic Bundle | 2024-11-21 | N/A | 6.1 MEDIUM |
|
The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 1.2.0 to receive a patch or, as a workaround, apply the patch manually.
|
|||||
| CVE-2023-46693 | 1 Formalms | 1 Formalms | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title parameters.
|
|||||
| CVE-2023-46659 | 1 Jenkins | 1 Edgewall Trac | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
|
|||||
| CVE-2023-46650 | 1 Jenkins | 1 Github | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
|
|||||
| CVE-2023-46643 | 1 Cloudnet360 | 1 Cloudnet360 | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions.
|
|||||
| CVE-2023-46642 | 1 Sahu | 1 Sahu Tiktok Pixel For E-commerce | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in sahumedia SAHU TikTok Pixel for E-Commerce plugin <= 1.2.2 versions.
|
|||||
| CVE-2023-46640 | 1 Mauvedev | 1 Medialist | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in D. Relton Medialist plugin <= 1.3.9 versions.
|
|||||
| CVE-2023-46627 | 1 Freelancer-coder | 1 Wordpress Simple Html Sitemap | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.
|
|||||
| CVE-2023-46622 | 1 Wp-pizza | 1 Wppizza | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.18.2 versions.
|
|||||
| CVE-2023-46621 | 1 Enejbajgoric\/gagansandhu\/ctltdev | 1 User Avatar | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.
|
|||||
| CVE-2023-46613 | 1 Add-to-calendar-button | 1 Add To Calendar Button | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jens Kuerschner Add to Calendar Button plugin <= 1.5.1 versions.
|
|||||
| CVE-2023-46583 | 1 Phpgurukul | 1 Nipah Virus Testing Management System | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field.
|
|||||
| CVE-2023-46580 | 1 Code-projects | 1 Inventory Management | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.
|
|||||
| CVE-2023-46505 | 1 Pwncyn | 1 Fancms | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in FanCMS v.1.0.0 allows an attacker to execute arbitrary code via the content1 parameter in the demo.php file.
|
|||||
| CVE-2023-46504 | 1 Pwncyn | 1 Yxbookcms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute arbitrary code via the library name function in the general settings component.
|
|||||
| CVE-2023-46503 | 1 Pwncyn | 1 Yxbookcms | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a remote attacker to execute arbitrary code via the reader management and book input modules.
|
|||||
| CVE-2023-46499 | 1 Evershop | 1 Evershop | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel.
|
|||||
| CVE-2023-46495 | 1 Evershop | 1 Evershop | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the sortBy parameter.
|
|||||
| CVE-2023-46492 | 1 Mldb | 1 Machine Learning Database | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html.
|
|||||
| CVE-2023-46491 | 1 Zentao | 1 Biz | 2024-11-21 | N/A | 6.1 MEDIUM |
|
ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library.
|
|||||
| CVE-2023-46483 | 1 Timeteccloud | 1 Auto Web-based Database Management System | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a crafted payload to the remark parameter of the New Zone function.
|
|||||
| CVE-2023-46475 | 1 Easycorp | 1 Zentao | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
|
|||||
| CVE-2023-46470 | 1 Spaceapplications | 1 Yacms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via crafted telecommand in the timeline view of the ArchiveBrowser.
|
|||||
| CVE-2023-46467 | 1 Juzaweb | 1 Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registration page.
|
|||||
| CVE-2023-46451 | 1 Mayurik | 1 Best Courier Management System | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.
|
|||||
| CVE-2023-46450 | 1 Mayurik | 1 Inventory Management System | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.
|
|||||
| CVE-2023-46448 | 1 Dmpop | 1 Mejiro | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to run arbitrary code via crafted string in metadata of uploaded images.
|
|||||
| CVE-2023-46396 | 1 Web-audimex | 1 Audimex | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters.
|
|||||
| CVE-2023-46394 | 1 Gougucms | 1 Gougucms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.
|
|||||
| CVE-2023-46378 | 1 1234n | 1 Minicms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.
|
|||||
| CVE-2023-46374 | 1 Zentao | 1 Biz | 2024-11-21 | N/A | 6.1 MEDIUM |
|
ZenTao Enterprise Edition version 4.1.3 and before is vulnerable to Cross Site Scripting (XSS).
|
|||||
| CVE-2023-46313 | 1 Katieseaborn | 1 Zotpress | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.4 versions.
|
|||||
| CVE-2023-46312 | 1 Zaytech | 1 Smart Online Order For Clover | 2024-11-21 | N/A | 7.1 HIGH |
|
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 versions.
|
|||||