Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1435 1 Wptaskforce 1 Track \& Trace 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2022-1433 1 Gitlab 1 Gitlab 2024-11-21 4.3 MEDIUM 2.6 LOW
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.
CVE-2022-1432 1 Octoprint 1 Octoprint 2024-11-21 4.6 MEDIUM 6.4 MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
CVE-2022-1431 1 Gitlab 1 Gitlab 2024-11-21 5.0 MEDIUM 4.3 MEDIUM
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.
CVE-2022-1430 1 Octoprint 1 Octoprint 2024-11-21 5.1 MEDIUM 7.5 HIGH
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.
CVE-2022-1418 1 Pluginmirror 1 Social Stickers 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape some of these fields, which could allow attackers to make a logged-in admin change them and lead to Stored Cross-Site Scripting issues.
CVE-2022-1416 1 Gitlab 1 Gitlab 2024-11-21 3.5 LOW 4.3 MEDIUM
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling
CVE-2022-1408 1 Vikwp 1 Hotel Booking Engine \& Pms 2024-11-21 3.5 LOW 4.8 MEDIUM
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1396 1 Donorbox 1 Donorbox 2024-11-21 3.5 LOW 4.8 MEDIUM
The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed
CVE-2022-1395 1 Easy Faq With Expanding Text Project 1 Easy Faq With Expanding Text 2024-11-21 3.5 LOW 4.8 MEDIUM
The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
CVE-2022-1394 1 10web 1 Photo Gallery 2024-11-21 3.5 LOW 4.8 MEDIUM
The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
CVE-2022-1393 1 Wp Subtitle Project 1 Wp Subtitle 2024-11-21 3.5 LOW 5.4 MEDIUM
The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subtitle]. The subtitle is stored as a custom post meta with the key: "wps_subtitle", which is sanitized upon post save/update, however is not sanitized when updating it directly from the post meta update button (via AJAX) - and this makes the XSS exploitable by authenticated users with a role as low as contributor.
CVE-2022-1387 1 No Future Posts Project 1 No Future Posts 2024-11-21 3.5 LOW 4.8 MEDIUM
The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
CVE-2022-1380 1 Snipeitapp 1 Snipe-it 2024-11-21 3.5 LOW 5.4 MEDIUM
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.
CVE-2022-1351 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.
CVE-2022-1347 1 Organizr 1 Organizr 2024-11-21 6.0 MEDIUM 8.4 HIGH
Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation
CVE-2022-1346 1 Organizr 1 Organizr 2024-11-21 3.5 LOW 9.0 CRITICAL
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
CVE-2022-1344 1 Organizr 1 Organizr 2024-11-21 3.5 LOW 9.0 CRITICAL
Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
CVE-2022-1340 1 Yetiforce 1 Yetiforce Customer Relationship Management 2024-11-21 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-1338 1 Commonninja 1 Easily Generate Rest Api 2024-11-21 3.5 LOW 4.8 MEDIUM
The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-1336 1 Ceikay 1 Carousel Ck 2024-11-21 3.5 LOW 4.8 MEDIUM
The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
CVE-2022-1335 1 Ceikay 1 Slideshow Ck 2024-11-21 3.5 LOW 4.8 MEDIUM
The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
CVE-2022-1334 1 Wp Youtube Live Project 1 Wp Youtube Live 2024-11-21 3.5 LOW 4.8 MEDIUM
The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1330 1 Fullpage Project 1 Fullpage 2024-11-21 3.5 LOW 5.4 MEDIUM
stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .
CVE-2022-1327 1 Rich-web 1 Image Gallery 2024-11-21 3.5 LOW 4.8 MEDIUM
The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1326 1 Form - Contact Form Project 1 Form - Contact Form 2024-11-21 3.5 LOW 4.8 MEDIUM
The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1324 1 Rich-web 1 Event Timeline 2024-11-21 N/A 4.8 MEDIUM
The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1322 1 Rich-web 1 Coming Soon 2024-11-21 N/A 4.8 MEDIUM
The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1321 1 Miniorange 1 Google Authenticator 2024-11-21 3.5 LOW 4.8 MEDIUM
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
CVE-2022-1320 1 10web 1 Sliderby10web 2024-11-21 3.5 LOW 4.8 MEDIUM
The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2022-1303 1 Slide Anything Project 1 Slide Anything 2024-11-21 3.5 LOW 4.8 MEDIUM
The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
CVE-2022-1301 1 Wpexperts 1 Wp Contact Slider 2024-11-21 3.5 LOW 4.8 MEDIUM
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
CVE-2022-1299 1 Slideshow Project 1 Slideshow 2024-11-21 3.5 LOW 4.8 MEDIUM
The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-1298 1 Wpshopmart 1 Tabs Responsive 2024-11-21 3.5 LOW 4.8 MEDIUM
The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-1294 1 99webtools 1 Imdb Info Box 2024-11-21 3.5 LOW 4.8 MEDIUM
The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2022-1293 1 Thalesgroup 1 Citadel 2024-11-21 N/A 5.7 MEDIUM
The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions.
CVE-2022-1291 1 Tableexport.jquery.plugin Project 1 Tableexport.jquery.plugin 2024-11-21 3.5 LOW 5.4 MEDIUM
XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. Transmitting cookies to third-party servers. Sending data from secure sessions to third-party servers
CVE-2022-1290 1 Trudesk Project 1 Trudesk 2024-11-21 3.5 LOW 5.4 MEDIUM
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
CVE-2022-1288 1 School Club Application System Project 1 School Club Application System 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue affects access to /scas/admin/. The manipulation of the parameter page with the input %22%3E%3Cimg%20src=x%20onerror=alert(1)%3E leads to a reflected cross site scripting. The attack may be initiated remotely and does not require any form of authentication. The exploit has been disclosed to the public and may be used.
CVE-2022-1282 1 10web 1 Photo Gallery 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the users when executing the editimage_bwg AJAX action.