Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46822 1 Visser 1 Store Exporter For Woocommerce 2024-11-21 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting') vulnerability in Visser Labs Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin <= 2.7.2 versions.
CVE-2023-46783 1 Brightplugins 1 Pre-orders For Woocommerce 2024-11-21 N/A 5.4 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bright Plugins Pre-Orders for WooCommerce plugin <= 1.2.13 versions.
CVE-2023-46782 1 Chrisyee 1 Momentopress For Momento360 2024-11-21 N/A 5.4 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Yee MomentoPress for Momento360 plugin <= 1.0.1 versions.
CVE-2023-46744 1 Squidex.io 1 Squidex 2024-11-21 N/A 5.4 MEDIUM
Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering mechanism intended to stop XSS attacks through uploaded SVG images, is insufficient resulting to stored XSS attacks. Squidex allows the CMS contributors to be granted the permission of uploading an SVG asset. When the asset is uploaded, a filtering mechanism is performed to validate ...

Show More

CVE-2023-46735 1 Sensiolabs 1 Symfony 2024-11-21 N/A 6.1 MEDIUM
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input in its response.
CVE-2023-46734 1 Sensiolabs 2 Symfony, Twig 2024-11-21 N/A 6.1 MEDIUM
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.
CVE-2023-46732 1 Xwiki 1 Xwiki 2024-11-21 N/A 9.6 CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to reflected cross-site scripting (RXSS) via the `rev` parameter that is used in the content of the content menu without escaping. If an attacker can convince a user to visit a link with a crafted parameter, this allows the attacker to execute arbitrary actions in the name of the user, including remote code (Groovy) execution in the case of a user with programming right, c ...

Show More

CVE-2023-46722 1 Pimcore 1 Admin Classic Bundle 2024-11-21 N/A 6.1 MEDIUM
The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 1.2.0 to receive a patch or, as a workaround, apply the patch manually.
CVE-2023-46693 1 Formalms 1 Formalms 2024-11-21 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title parameters.
CVE-2023-46659 1 Jenkins 1 Edgewall Trac 2024-11-21 N/A 5.4 MEDIUM
Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2023-46650 1 Jenkins 1 Github 2024-11-21 N/A 5.4 MEDIUM
Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2023-46643 1 Cloudnet360 1 Cloudnet360 2024-11-21 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions.
CVE-2023-46642 1 Sahu 1 Sahu Tiktok Pixel For E-commerce 2024-11-21 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in sahumedia SAHU TikTok Pixel for E-Commerce plugin <= 1.2.2 versions.
CVE-2023-46640 1 Mauvedev 1 Medialist 2024-11-21 N/A 5.4 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in D. Relton Medialist plugin <= 1.3.9 versions.
CVE-2023-46627 1 Freelancer-coder 1 Wordpress Simple Html Sitemap 2024-11-21 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.
CVE-2023-46622 1 Wp-pizza 1 Wppizza 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.18.2 versions.
CVE-2023-46621 1 Enejbajgoric\/gagansandhu\/ctltdev 1 User Avatar 2024-11-21 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.
CVE-2023-46613 1 Add-to-calendar-button 1 Add To Calendar Button 2024-11-21 N/A 5.4 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jens Kuerschner Add to Calendar Button plugin <= 1.5.1 versions.
CVE-2023-46583 1 Phpgurukul 1 Nipah Virus Testing Management System 2024-11-21 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field.
CVE-2023-46580 1 Code-projects 1 Inventory Management 2024-11-21 N/A 5.4 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.
CVE-2023-46505 1 Pwncyn 1 Fancms 2024-11-21 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in FanCMS v.1.0.0 allows an attacker to execute arbitrary code via the content1 parameter in the demo.php file.
CVE-2023-46504 1 Pwncyn 1 Yxbookcms 2024-11-21 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute arbitrary code via the library name function in the general settings component.
CVE-2023-46503 1 Pwncyn 1 Yxbookcms 2024-11-21 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a remote attacker to execute arbitrary code via the reader management and book input modules.
CVE-2023-46499 1 Evershop 1 Evershop 2024-11-21 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel.
CVE-2023-46495 1 Evershop 1 Evershop 2024-11-21 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the sortBy parameter.
CVE-2023-46492 1 Mldb 1 Machine Learning Database 2024-11-21 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html.
CVE-2023-46491 1 Zentao 1 Biz 2024-11-21 N/A 6.1 MEDIUM
ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library.
CVE-2023-46483 1 Timeteccloud 1 Auto Web-based Database Management System 2024-11-21 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a crafted payload to the remark parameter of the New Zone function.
CVE-2023-46475 1 Easycorp 1 Zentao 2024-11-21 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
CVE-2023-46470 1 Spaceapplications 1 Yacms 2024-11-21 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via crafted telecommand in the timeline view of the ArchiveBrowser.
CVE-2023-46467 1 Juzaweb 1 Cms 2024-11-21 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registration page.
CVE-2023-46451 1 Mayurik 1 Best Courier Management System 2024-11-21 N/A 5.4 MEDIUM
Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.
CVE-2023-46450 1 Mayurik 1 Inventory Management System 2024-11-21 N/A 5.4 MEDIUM
Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.
CVE-2023-46448 1 Dmpop 1 Mejiro 2024-11-21 N/A 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to run arbitrary code via crafted string in metadata of uploaded images.
CVE-2023-46396 1 Web-audimex 1 Audimex 2024-11-21 N/A 5.4 MEDIUM
Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters.
CVE-2023-46394 1 Gougucms 1 Gougucms 2024-11-21 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.
CVE-2023-46378 1 1234n 1 Minicms 2024-11-21 N/A 5.4 MEDIUM
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.
CVE-2023-46374 1 Zentao 1 Biz 2024-11-21 N/A 6.1 MEDIUM
ZenTao Enterprise Edition version 4.1.3 and before is vulnerable to Cross Site Scripting (XSS).
CVE-2023-46313 1 Katieseaborn 1 Zotpress 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.4 versions.
CVE-2023-46312 1 Zaytech 1 Smart Online Order For Clover 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 versions.