Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-25303 | 1 Whoogle-search Project | 1 Whoogle-search | 2024-11-21 | 4.3 MEDIUM | 5.4 MEDIUM |
|
The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the [flask.render_template](https://flask.palletsprojects.com/en/2.1.x/api/flask.render_template) function. However, the error_message is rendered using the [| safe filter](https://jinja.palletsprojects.com/en/3.1.x/templates/workin ...
Show More |
|||||
| CVE-2022-25269 | 1 Passwork | 1 Passwork | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Passwork On-Premise Edition before 4.6.13 has multiple XSS issues.
|
|||||
| CVE-2022-25261 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
|
|||||
| CVE-2022-25259 | 1 Jetbrains | 1 Hub | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
|
|||||
| CVE-2022-25256 | 6 Hpe, Ibm, Linux and 3 more | 6 Hp-ux Ipfilter, Aix, Linux Kernel and 3 more | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after pressing the button, e.g., a malicious web page. In addition, the second parameter executes JavaScript, which means XSS is possible by adding a javascript: URL.
|
|||||
| CVE-2022-25238 | 1 Silverstripe | 1 Framework | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
|
|||||
| CVE-2022-25229 | 1 Popcorn Time Project | 1 Popcorn Time | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.
|
|||||
| CVE-2022-25224 | 1 Proton Project | 1 Proton | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Proton v0.2.0 allows an attacker to create a malicious link inside a markdown file. When the victim clicks the link, the application opens the site in the current frame allowing an attacker to host JavaScript code in the malicious link in order to trigger an XSS attack. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.
|
|||||
| CVE-2022-25221 | 1 Money Transfer Management System Project | 1 Money Transfer Management System | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Money Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a user into visit the link in order to execute JavaScript code.
|
|||||
| CVE-2022-25220 | 1 Petereport Project | 1 Petereport | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while creating a product, report or finding.
|
|||||
| CVE-2022-25203 | 1 Jenkins | 1 Team Views | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Read permission.
|
|||||
| CVE-2022-25202 | 1 Jenkins | 1 Promoted Builds \(simple\) | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion levels, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
|
|||||
| CVE-2022-25191 | 1 Jenkins | 1 Agent Server Parameter | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
|
|||||
| CVE-2022-25189 | 1 Jenkins | 1 Custom Checkbox Parameter | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
|
|||||
| CVE-2022-25185 | 1 Jenkins | 1 Generic Webhook Trigger | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
|
|||||
| CVE-2022-25138 | 1 Axelor | 1 Open Suite | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name parameter.
|
|||||
| CVE-2022-25114 | 1 Event Management Project | 1 Event Management | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name parameter under register.php.
|
|||||
| CVE-2022-25069 | 1 Marktext | 1 Marktext | 2024-11-21 | 6.8 MEDIUM | 9.6 CRITICAL |
|
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.
|
|||||
| CVE-2022-25038 | 2024-11-21 | N/A | 6.1 MEDIUM | ||
|
wanEditor v4.7.11 was discovered to contain a cross-site scripting (XSS) vulnerability via the video upload function.
|
|||||
| CVE-2022-25037 | 2024-11-21 | N/A | 5.4 MEDIUM | ||
|
An issue in wanEditor v4.7.11 and fixed in v.4.7.12 and v.5 was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function.
|
|||||
| CVE-2022-25028 | 1 Home Owners Collection Management System Project | 1 Home Owners Collection Management System | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.
|
|||||
| CVE-2022-25022 | 1 Htmly | 1 Htmly | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.
|
|||||
| CVE-2022-25020 | 1 Pluxml | 1 Pluxml | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
|
|||||
| CVE-2022-25015 | 1 Icehrm | 1 Icehrm | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field.
|
|||||
| CVE-2022-25014 | 1 Icehrm | 1 Icehrm | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session credentials via user interaction with a crafted link.
|
|||||
| CVE-2022-25013 | 1 Icehrm | 1 Icehrm | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php.
|
|||||
| CVE-2022-24981 | 1 Jqueryform | 1 Jqueryform | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to admin.php.
|
|||||
| CVE-2022-24957 | 1 Dhc-vision | 1 Eqms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
DHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit the vulnerability, the attacker has to create or edit a new information object and use the XSS payload as the name. Any user that opens the object's version or history tab will be attacked.
|
|||||
| CVE-2022-24948 | 1 Apache | 1 Jspwiki | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.2 or later.
|
|||||
| CVE-2022-24926 | 1 Samsung | 1 Smarttagplugin | 2024-11-21 | 3.5 LOW | 5.7 MEDIUM |
|
Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.
|
|||||
| CVE-2022-24899 | 1 Contao | 1 Contao | 2024-11-21 | 4.3 MEDIUM | 7.2 HIGH |
|
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.
|
|||||
| CVE-2022-24876 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a cross site scripting vulnerability in Kanban by injecting HTML code in its user name. Users are advised to upgrade. There are no known workarounds for this issue.
|
|||||
| CVE-2022-24873 | 1 Shopware | 1 Shopware | 2024-11-21 | 4.3 MEDIUM | 5.4 MEDIUM |
|
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.
|
|||||
| CVE-2022-24870 | 1 Combodo | 1 Itop | 2024-11-21 | 3.5 LOW | 8.7 HIGH |
|
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system. Users are advised to upgrade. There are no known workarounds for this issue.
|
|||||
| CVE-2022-24869 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 3.5 LOW | 4.6 MEDIUM |
|
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use ticket's followups or setup login messages with a stylesheet link. This may allow for a cross site scripting attack vector. This issue is partially mitigated by cors security of browsers, though users are still advised to upgrade.
|
|||||
| CVE-2022-24868 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 3.5 LOW | 7.3 HIGH |
|
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a result any user viewing the avatar will be subject to a cross site scripting attack. Users of GLPI are advised to upgrade. Users unable to upgrade should disallow SVG avatars.
|
|||||
| CVE-2022-24864 | 1 Originprotocol | 1 Origin Website | 2024-11-21 | 3.5 LOW | 4.1 MEDIUM |
|
Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is delivered to the [email protected]. If the email recipient is using an email program that is susceptible to XSS, then that email recipient will receive an email that may contain malicious XSS. Regardless if the ...
Show More |
|||||
| CVE-2022-24855 | 1 Metabase | 1 Metabase | 2024-11-21 | 3.5 LOW | 8.7 HIGH |
|
Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links that could lead to account takeover. Users are advised to either upgrade immediately, or block access in your firewall to `/_internal` endpoints for Metabase. The following patches (or greater versions) are available: 0. ...
Show More |
|||||
| CVE-2022-24851 | 2 Debian, Ldap-account-manager | 2 Debian Linux, Ldap Account Manager | 2024-11-21 | 3.5 LOW | 8.1 HIGH |
|
LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated user can store XSS payloads in the profiles, which gets triggered when any other user try to access the edit profile page. The pdf editor tool has an edit pdf profile functionality, the logoFile parameter in it is not prop ...
Show More |
|||||
| CVE-2022-24833 | 1 Privatebin | 1 Privatebin | 2024-11-21 | 4.3 MEDIUM | 8.2 HIGH |
|
PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the time still called ZeroBin. The issue is caused by the fact that SVGs can contain JavaScript. This can allow an attacker to execute code, if the user opens a paste with a specifically crafted SVG attachment, and interacts w ...
Show More |
|||||