Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29452 1 Atlasgondal 1 Export All Urls 2024-11-21 3.5 LOW 3.4 LOW
Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.
CVE-2022-29449 1 Wpopal 1 Opal Hotel Room Booking 2024-11-21 3.5 LOW 4.1 MEDIUM
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booking plugin <= 1.2.7 at WordPress.
CVE-2022-29444 1 Cloudways 1 Breeze 2024-11-21 3.5 LOW 6.5 MEDIUM
Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to execute any of the wp_ajax_* actions in the class Breeze_Configuration which includes the ability to change any of the plugin's settings including CDN setting which could be further used for XSS attack.
CVE-2022-29443 1 Nicdark 1 Hotel Booking 2024-11-21 3.5 LOW 4.1 MEDIUM
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress.
CVE-2022-29442 1 Private Messages Project 1 Private Messages 2024-11-21 3.5 LOW 5.4 MEDIUM
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress.
CVE-2022-29440 1 Promotion Slider Project 1 Promotion Slider 2024-11-21 3.5 LOW 5.4 MEDIUM
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Promotion Slider plugin <= 3.3.4 at WordPress.
CVE-2022-29438 1 Nextcode 1 Image Slider By Nextcode 2024-11-21 3.5 LOW 4.8 MEDIUM
Authenticated (author or higher user role) Persistent Cross-Site Scripting (XSS) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
CVE-2022-29436 1 Code Snippets Extended Project 1 Code Snippets Extended 2024-11-21 4.3 MEDIUM 4.7 MEDIUM
Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code).
CVE-2022-29433 1 Donations Project 1 Donations 2024-11-21 3.5 LOW 4.1 MEDIUM
Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.
CVE-2022-29432 1 Tms-outsource 1 Wpdatatables 2024-11-21 3.5 LOW 3.4 LOW
Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin <= 2.1.27 on WordPress via &data-link-text, &data-link-url, &data, &data-shortcode, &data-star-num vulnerable parameters.
CVE-2022-29430 1 Png To Jpg Project 1 Png To Jpg 2024-11-21 4.3 MEDIUM 4.7 MEDIUM
Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter &jpg_quality.
CVE-2022-29428 1 Muneeb 1 Wp Slider 2024-11-21 3.5 LOW 4.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Muneeb's WP Slider Plugin <= 1.4.5 at WordPress.
CVE-2022-29426 1 2joomla 1 2j Slideshow 2024-11-21 3.5 LOW 5.4 MEDIUM
Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin <= 1.3.54 at WordPress.
CVE-2022-29425 1 Wpwham 1 Checkout Files Upload For Woocommerce 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress.
CVE-2022-29424 1 Oxilab 1 Image Hover Effects Ultimate 2024-11-21 3.5 LOW 4.8 MEDIUM
Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin <= 9.7.1 at WordPress.
CVE-2022-29422 1 Edmonsoft 1 Countdown Builder 2024-11-21 3.5 LOW 4.8 MEDIUM
Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, &ycd-button-margin-top, &ycd-button-margin-right, &ycd-button-margin-bottom, &ycd-button-margin-left, &ycd-circle-countdown-before-countdown, &ycd-circle-countdown-after-countdown vulnerable parameters.
CVE-2022-29421 1 Edmonsoft 1 Countdown Builder 2024-11-21 4.3 MEDIUM 4.7 MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type vulnerable parameter.
CVE-2022-29420 1 Edmonsoft 1 Countdown Builder 2024-11-21 3.5 LOW 5.9 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock (WordPress plugin) countdown-builder allows Stored XSS.This issue affects Countdown & Clock (WordPress plugin): from n/a through 2.3.2.
CVE-2022-29418 1 Night Mode Project 1 Night Mode 2024-11-21 3.5 LOW 4.8 MEDIUM
Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &ntmode_page_setting[txt-color], &ntmode_page_setting[anc_color].
CVE-2022-29416 1 Afterpay 1 Afterpay Gateway For Woocommerce 2024-11-21 N/A 4.7 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.
CVE-2022-29415 1 Ravpage Project 1 Ravpage 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 at WordPress.
CVE-2022-29413 1 Hermit Project 1 Hermit 2024-11-21 4.3 MEDIUM 4.7 MEDIUM
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title parameter.
CVE-2022-29408 1 Vsourz 1 Advanced Cf7 Db 2024-11-21 4.3 MEDIUM 4.7 MEDIUM
Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress.
CVE-2022-29406 1 Dynamicweblab 1 Wp-team-manager 2024-11-21 3.5 LOW 4.1 MEDIUM
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in DynamicWebLab's WordPress Team Manager plugin <= 1.6.9 at WordPress.
CVE-2022-29380 1 Creativeitem 1 Academy Lms 2024-11-21 3.5 LOW 4.8 MEDIUM
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
CVE-2022-29360 1 Rainloop 1 Webmail 2024-11-21 N/A 5.4 MEDIUM
The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
CVE-2022-29359 1 School Club Application System Project 1 School Club Application System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.
CVE-2022-29349 1 Keking 1 Kkfileview 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
CVE-2022-29296 1 Avantune 1 Genialcloud Proj 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-29273 1 Netgate 1 Pfsense 2024-11-21 N/A 6.1 MEDIUM
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
CVE-2022-29269 1 Nagios 1 Nagios Xi 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
CVE-2022-29258 1 Xwiki 1 Xwiki 2024-11-21 4.3 MEDIUM 7.4 HIGH
XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream. Starting with versions 6.0-milestone-2 and 5.4.4 and prior to versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3, XWiki Platform Filter UI contains a possible cross-site scripting vector in the `Filter.FilterStreamDescriptorForm` wiki page related to pretty much all the form fields printed in the home page of the application. The issue is patche ...

Show More

CVE-2022-29252 1 Xwiki 1 Xwiki 2024-11-21 4.3 MEDIUM 7.4 HIGH
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the `WikiManager.JoinWiki ` wiki page related to the "requestJoin" field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page `WikiManager.JoinWiki` (with wiki editor) according to the suggestion provided in the GitHub Security ...

Show More

CVE-2022-29251 1 Xwiki 1 Xwiki 2024-11-21 4.3 MEDIUM 7.4 HIGH
XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the `FlamingoThemesCode.WebHomeSheet` wiki page related to the "newThemeName" form field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page `FlamingoThemesCode.WebHomeSheet` (with wiki editor) according to the su ...

Show More

CVE-2022-29230 1 Shopify 1 Hydrogen 2024-11-21 3.5 LOW 6.3 MEDIUM
Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross-Site Scripting (XSS) vulnerability where an arbitrary user is able to execute scripts on pages that are built with Hydrogen. This affects all versions of Hydrogen starting from version 0.10.0 to 0.18.0. This vulnerability is exploitable in applications whose hydrating data is user controlled. All Hydrogen users should upgrade their project to version 0.19.0. There is no curren ...

Show More

CVE-2022-29183 1 Thoughtworks 1 Gocd 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim into executing code which would allow the attacker to operate on, or gain control over the same resources as the victim had access to. This issue is fixed in GoCD 21.4.0. As a workaround, block access to `/go/compare/.*` ...

Show More

CVE-2022-29182 1 Thoughtworks 1 Gocd 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It is possible for a malicious script on a attacker-hosted site to execute script that will run within the user's browser context and GoCD session via abuse of a messaging channel used for communication between with the parent page and the stage details graph's iframe. This could a ...

Show More

CVE-2022-29172 1 Auth0 1 Lock 2024-11-21 2.6 LOW 6.1 MEDIUM
Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Salesforce. In versions before `11.33.0`, when the “additional signup fields” feature [is configured](https://github.com/auth0/lock#additional-sign-up-fields), a malicious actor can inject invalidated HTML code into these additional fields, which is then stored in the service `user_metdata` payload (using the `name` property). Verification emails, when ...

Show More

CVE-2022-29168 1 Wire 1 Wire-webapp 2024-11-21 4.3 MEDIUM 9.6 CRITICAL
Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient escaping when rendering `@mentions` in the wire-webapp. If a user receives and views a malicious message, arbitrary code is injected and executed in the context of the victim allowing the attacker to fully control the user account. Wire-desktop clients that are connected to a vulnerable wire-webapp version are also vulnerable to this attack. The issue has been fixed in wire-weba ...

Show More

CVE-2022-29152 1 Ericom 1 Powerterm Webconnect 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page.