Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-36197 | 1 Bigtreecms | 1 Bigtree Cms | 2024-11-21 | N/A | 5.4 MEDIUM |
|
BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file.
|
|||||
| CVE-2022-36194 | 1 Centreon | 1 Centreon | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.
|
|||||
| CVE-2022-36131 | 1 Midori-global | 1 Better Pdf Exporter | 2024-11-21 | N/A | 6.1 MEDIUM |
|
The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Templates overview page.
|
|||||
| CVE-2022-36108 | 1 Typo3 | 1 Typo3 | 2024-11-21 | N/A | 6.5 MEDIUM |
|
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `f:asset.css` view helper is vulnerable to cross-site scripting when user input is passed as variables to the CSS. Update to TYPO3 version 10.4.32 or 11.5.16 that fix the problem. There are no known workarounds for this issue.
|
|||||
| CVE-2022-36107 | 1 Typo3 | 1 Typo3 | 2024-11-21 | N/A | 6.5 MEDIUM |
|
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the `FileDumpController` (backend and frontend context) is vulnerable to cross-site scripting when malicious files are displayed using this component. A valid backend user account is needed to exploit this vulnerability. Update to TYPO3 version 7.6.58 ELTS, 8.7.48 ELTS, 9.5.37 ELTS, 10.4.32 or 11.5.16 that fix the problem. There are no known workarounds for this issue.
|
|||||
| CVE-2022-36098 | 1 Xwiki | 1 Xwiki | 2024-11-21 | N/A | 8.9 HIGH |
|
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor, or reference field. The stored code is executed by anyone visiting the page with the mention. This issue has been patched on XWiki 14.4 and 13.10.6. As a workaround, one may update `XWiki.Mentions.MentionsMacro` and edit ...
Show More |
|||||
| CVE-2022-36097 | 1 Xwiki | 1 Xwiki | 2024-11-21 | N/A | 8.9 HIGH |
|
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which will be executed by anyone trying to move the corresponding attachment. This issue has been patched in XWiki 14.4-rc-1. As a workaround, one may copy `moveStep1.vm` to `webapp/xwiki/templates/moveStep1.vm` and replace vulnerable code with code from t ...
Show More |
|||||
| CVE-2022-36096 | 1 Xwiki | 1 Xwiki | 2024-11-21 | N/A | 8.9 HIGH |
|
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3. As a workaround, modify fix the vulnerability by editing the wiki page `XWiki.DeletedAttachments ...
Show More |
|||||
| CVE-2022-36094 | 1 Xwiki | 1 Xwiki | 2024-11-21 | N/A | 8.9 HIGH |
|
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing the history of an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3RC1. As a workaround, it is possible to replace `viewattachrev.vm`, the entry point for this attack, by a patched version from the pat ...
Show More |
|||||
| CVE-2022-36080 | 1 Wikmd Project | 1 Wikmd | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, an attacker could capture user's session cookies or execute malicious Javascript when a victim edits a markdown file. Version 1.7.1 fixes this issue.
|
|||||
| CVE-2022-36057 | 1 Discourse | 1 Discourse-chat | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse Chat can be affected by admin users inserting HTML into chat titles and descriptions, causing a Cross-Site Scripting (XSS) attack. Version 0.9 contains a patch for this issue.
|
|||||
| CVE-2022-36037 | 1 Getkirby | 1 Kirby | 2024-11-21 | N/A | 5.9 MEDIUM |
|
kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal interface. Cross-site scripting (XSS) is a type of vulnerability that allows execution of any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. If bad actors gain access to your group of authenticated Panel users they can escalate their priv ...
Show More |
|||||
| CVE-2022-36033 | 2 Jsoup, Netapp | 4 Jsoup, Management Services For Element Software, Management Services For Netapp Hci and 1 more | 2024-11-21 | N/A | 6.1 MEDIUM |
|
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Con ...
Show More |
|||||
| CVE-2022-36020 | 1 Typo3 | 1 Html Sanitizer | 2024-11-21 | N/A | 6.1 MEDIUM |
|
The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special HTML comments cannot be filtered and sanitized. This allows for a bypass of the cross-site scripting mechanism of `typo3/html-sanitizer`. This issue has been addressed in versions 1.0.7 and 2.0.16 of the `typo3/html-sanit ...
Show More |
|||||
| CVE-2022-35950 | 1 Oroinc | 1 Orocommerce | 2024-11-21 | N/A | 6.9 MEDIUM |
|
OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through 4.2.10, 5.0.0 prior to 5.0.11, and 5.1.0 prior to 5.1.1, the JS payload added to the product name may be executed at the storefront when adding a note to the shopping list line item containing a vulnerable product. An attacker should be able to edit a product in the admin area and force a user to add this product to Shopping List and click add a note for it. Versions 5.0.11 an ...
Show More |
|||||
| CVE-2022-35945 | 1 Glpi-project | 1 Glpi | 2024-11-21 | N/A | 6.3 MEDIUM |
|
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Information associated to registration key are not properly escaped in registration key configuration page. They can be used to steal a GLPI administrator cookie. Users are advised to upgrade to 10.0.3. There are no known workarounds for this issue. ### Workarounds Do not use a registration key created b ...
Show More |
|||||
| CVE-2022-35933 | 1 Prestashop | 1 Productcomments | 2024-11-21 | N/A | 6.1 MEDIUM |
|
This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.
|
|||||
| CVE-2022-35910 | 1 Jellyfin | 1 Jellyfin | 2024-11-21 | N/A | 5.4 MEDIUM |
|
In Jellyfin before 10.8, stored XSS allows theft of an admin access token.
|
|||||
| CVE-2022-35882 | 1 Gsplugins | 1 Gs Testimonial Slider | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial Slider plugin <= 1.9.5 at WordPress.
|
|||||
| CVE-2022-35851 | 1 Fortinet | 1 Fortiadc | 2024-11-21 | N/A | 8.0 HIGH |
|
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted IP Address.
|
|||||
| CVE-2022-35850 | 1 Fortinet | 1 Fortiauthenticator | 2024-11-21 | N/A | 4.3 MEDIUM |
|
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page.
|
|||||
| CVE-2022-35725 | 1 Wp-forecast Project | 1 Wp-forecast | 2024-11-21 | N/A | 4.8 MEDIUM |
|
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at WordPress.
|
|||||
| CVE-2022-35714 | 1 Ibm | 1 Maximo Asset Management | 2024-11-21 | N/A | 5.4 MEDIUM |
|
IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231116.
|
|||||
| CVE-2022-35698 | 1 Adobe | 2 Commerce, Magento Open Source | 2024-11-21 | N/A | 10.0 CRITICAL |
|
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.
|
|||||
| CVE-2022-35697 | 1 Adobe | 1 Web Content Management Core Components | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires a low author privilege access.
|
|||||
| CVE-2022-35696 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
|
|||||
| CVE-2022-35695 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
|
|||||
| CVE-2022-35694 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
|
|||||
| CVE-2022-35693 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
|
|||||
| CVE-2022-35655 | 1 Pega | 1 Pega Platform | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
|
|||||
| CVE-2022-35654 | 1 Pega | 1 Pega Platform | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
|
|||||
| CVE-2022-35653 | 3 Fedoraproject, Moodle, Redhat | 3 Fedora, Moodle, Enterprise Linux | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact a ...
Show More |
|||||
| CVE-2022-35651 | 3 Fedoraproject, Moodle, Redhat | 3 Fedora, Moodle, Enterprise Linux | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.
|
|||||
| CVE-2022-35645 | 1 Ibm | 2 Maximo Application Suite, Maximo Asset Management | 2024-11-21 | N/A | 6.4 MEDIUM |
|
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230958.
|
|||||
| CVE-2022-35632 | 1 Rapid7 | 1 Velociraptor | 2024-11-21 | N/A | 4.8 MEDIUM |
|
The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2.
|
|||||
| CVE-2022-35630 | 1 Rapid7 | 1 Velociraptor | 2024-11-21 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2.
|
|||||
| CVE-2022-35590 | 1 Fork-cms | 1 Fork Cms | 2024-11-21 | N/A | 4.8 MEDIUM |
|
A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "end_date" Parameter
|
|||||
| CVE-2022-35589 | 1 Fork-cms | 1 Fork Cms | 2024-11-21 | N/A | 4.8 MEDIUM |
|
A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_time" Parameter.
|
|||||
| CVE-2022-35587 | 1 Fork-cms | 1 Fork Cms | 2024-11-21 | N/A | 4.8 MEDIUM |
|
A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_date" Parameter
|
|||||
| CVE-2022-35585 | 1 Fork-cms | 1 Fork Cms | 2024-11-21 | N/A | 4.8 MEDIUM |
|
A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "start_date" Parameter
|
|||||