Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38306 1 Webmin 1 Webmin 2024-11-21 N/A 6.1 MEDIUM
An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.
CVE-2023-38305 1 Webmin 1 Webmin 2024-11-21 N/A 6.1 MEDIUM
An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a crafted download path containing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when the download link is accessed.
CVE-2023-38304 1 Webmin 1 Webmin 2024-11-21 N/A 5.4 MEDIUM
An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality, allowing an attacker to store a malicious payload in the Group Name field when creating a new group.
CVE-2023-38303 1 Webmin 1 Webmin 2024-11-21 N/A 5.4 MEDIUM
An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Command Execution (RCE) through the Users and Group's real name parameter.
CVE-2023-38255 1 Socomec 2 Modulys Gp, Modulys Gp Firmware 2024-11-21 N/A 6.5 MEDIUM
A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploading new device configuration that could affect the intended function of the device.
CVE-2023-38219 1 Adobe 2 Commerce, Magento 2024-11-21 N/A 8.7 HIGH
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Payload is stored in an admin area, resulting in high confidentiality and integri ...

Show More

CVE-2023-38215 1 Adobe 2 Experience Manager, Experience Manager Cloud Service 2024-11-21 N/A 5.4 MEDIUM
Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
CVE-2023-38214 1 Adobe 1 Experience Manager 2024-11-21 N/A 5.4 MEDIUM
Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
CVE-2023-38194 1 Superwebmailer 1 Superwebmailer 2024-11-21 N/A 6.1 MEDIUM
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
CVE-2023-38192 1 Superwebmailer 1 Superwebmailer 2024-11-21 N/A 6.1 MEDIUM
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.
CVE-2023-38191 1 Superwebmailer 1 Superwebmailer 2024-11-21 N/A 6.1 MEDIUM
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.
CVE-2023-38164 1 Microsoft 1 Dynamics 365 2024-11-21 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-38138 1 F5 19 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 16 more 2024-11-21 N/A 7.5 HIGH
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2023-38066 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
CVE-2023-38065 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
CVE-2023-38063 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
CVE-2023-38061 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
CVE-2023-38057 1 Otrs 1 Survey 2024-11-21 N/A 4.1 MEDIUM
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.
CVE-2023-38045 1 Admiror-design-studio 1 Admiror Gallery 2024-11-21 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
CVE-2023-38040 1 Revive-adserver 1 Revive Adserver 2024-11-21 N/A 6.1 MEDIUM
A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..
CVE-2023-38000 1 Wordpress 2 Gutenberg, Wordpress 2024-11-21 N/A 6.5 MEDIUM
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.
CVE-2023-37997 1 Dharmeshpatel 1 Post List With Featured Image 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dharmesh Patel Post List With Featured Image plugin <= 1.2 versions.
CVE-2023-37994 1 Wpruse 1 Art Decoration Shortcode 2024-11-21 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Artem Abramovich Art Decoration Shortcode plugin <= 1.5.6 versions.
CVE-2023-37993 1 Maennchen1 1 Wpshopgermany It-recht Kanzlei 2024-11-21 N/A 5.9 MEDIUM
Auth. Stored Cross-Site Scripting (XSS) vulnerability in maennchen1.De wpShopGermany IT-RECHT KANZLEI plugin <= 1.7 versions.
CVE-2023-37988 1 Creative-solutions 1 Contact Form Generator 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.
CVE-2023-37986 1 Minorange 1 Wordpress Yourmembership Single Sign-on 2024-11-21 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange YourMembership Single Sign On – YM SSO Login plugin <= 1.1.3 versions.
CVE-2023-37983 1 Keegnotrub 1 Art Direction 2024-11-21 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Noël Jackson Art Direction plugin <= 0.2.4 versions.
CVE-2023-37981 1 Wpkube 1 Authors List 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPKube Authors List plugin <= 2.0.2 versions.
CVE-2023-37980 1 Custom Field For Wp Job Manager Project 1 Custom Field For Wp Job Manager 2024-11-21 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Custom Field For WP Job Manager plugin <= 1.1 versions.
CVE-2023-37979 1 Ninjaforms 1 Ninja Forms 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
CVE-2023-37976 1 Radioforge 1 Radio Forge Muses Player With Skins 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Radio Forge Muses Player with Skins plugin <= 2.5 versions.
CVE-2023-37975 1 Variation Swatches For Woocommerce Project 1 Variation Swatches For Woocommerce 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Swatches for WooCommerce plugin <= 2.3.7 versions.
CVE-2023-37970 1 Mf Gig Calendar Project 1 Mf Gig Calendar 2024-11-21 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Matthew Fries MF Gig Calendar plugin <= 1.2 versions.
CVE-2023-37908 1 Xwiki 1 Xwiki-rendering 2024-11-21 N/A 9.0 CRITICAL
XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XHTML rendering, introduced in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid attribute names. This can be exploited, e.g., via the link syntax in any content that supports XWiki syntax like comments in XWiki. When a user moves the mouse over a malicious link, the malicious JavaScript code is ...

Show More

CVE-2023-37905 1 Ckeditor-wordcount-plugin Project 1 Ckeditor-wordcount-plugin 2024-11-21 N/A 6.1 MEDIUM
ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2023-37901 1 Cern 1 Indico 2024-11-21 N/A 5.4 MEDIUM
Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerability in confirmation prompts commonly used when deleting content from Indico. Exploitation requires someone with at least submission privileges (such as a speaker) and then someone else to attempt to delete this content. Considering that event organizers may want to delete suspicious-looking content when spotting it, there is a non-negligible risk of such an attack to succeed. Th ...

Show More

CVE-2023-37894 1 Radiustheme 1 Variation Images Gallery For Woocommerce 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Images Gallery for WooCommerce plugin <= 2.3.3 versions.
CVE-2023-37893 1 Chop-chop 1 Coming Soon Chop Chop 2024-11-21 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chop-Chop Coming Soon Chop Chop plugin <= 2.2.4 versions.
CVE-2023-37875 1 Wftpserver 1 Wing Ftp Server 2024-11-21 N/A 3.0 LOW
Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0.
CVE-2023-37874 1 Riverside 1 Http Headers 2024-11-21 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dimitar Ivanov HTTP Headers plugin <= 1.18.11 versions.