Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-28382 | 1 Zohocorp | 1 Manageengine Key Manager Plus | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
|
|||||
| CVE-2021-28380 | 1 Aimeos Project | 1 Aimeos | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows XSS via a backend user account.
|
|||||
| CVE-2021-28378 | 1 Gitea | 1 Gitea | 2024-11-21 | 3.5 LOW | 3.7 LOW |
|
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
|
|||||
| CVE-2021-28359 | 1 Apache | 1 Airflow | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.10.15 in 1.x series and affects 2.0.0 and 2.0.1 and 2.x series. This is the same as CVE-2020-13944 & CVE-2020-17515 but the implemented fix did not fix the issue completely. Update to Airflow 1.10.15 or 2.0.2. Please also update your Python version to the latest available PATCH releases of the installed MINOR versions, example update to Python 3.6.13 ...
Show More |
|||||
| CVE-2021-28290 | 1 Identityserver4.admin Project | 1 Identityserver4.admin | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.
|
|||||
| CVE-2021-28280 | 1 Php-fusion | 1 Phpfusion | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
|
|||||
| CVE-2021-28247 | 1 Ca | 1 Ehealth Performance Manager | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and perform a Reflected Cross-Site Scripting attack against the platform users. The affected endpoints are: cgi/nhWeb with the parameter report, aviewbin/filtermibobjects.pl with the parameter namefilter, and aviewbin/query.pl with the parameters System, SystemText, ...
Show More |
|||||
| CVE-2021-28161 | 1 Eclipse | 1 Theia | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
|
|||||
| CVE-2021-28160 | 1 Acexy Wireless-n Wifi Repeater Project | 2 Acexy Wireless-n Wifi Repeater, Acexy Wireless-n Wifi Repeater Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homepage section).
|
|||||
| CVE-2021-28145 | 1 Concretecms | 1 Concrete Cms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.
|
|||||
| CVE-2021-28126 | 1 Compassplus | 1 Tranzware E-commerce Payment Gateway | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability
|
|||||
| CVE-2021-28115 | 1 Ougc Feedback Project | 1 Ougc Feedback | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.
|
|||||
| CVE-2021-28114 | 1 Froala | 1 Froala Editor | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.
|
|||||
| CVE-2021-28109 | 1 Compassplus | 1 Tranzware Fimi | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).
|
|||||
| CVE-2021-28088 | 1 Impresscms | 1 Impresscms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.
|
|||||
| CVE-2021-28079 | 1 Jamovi | 1 Jamovi | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An attacker can make a .omv (Jamovi) document containing a payload. When opened by victim, the payload is triggered.
|
|||||
| CVE-2021-28054 | 1 Centreon | 1 Centreon | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter.
|
|||||
| CVE-2021-28047 | 1 Devolutions | 1 Remote Desktop Manager | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.
|
|||||
| CVE-2021-28007 | 1 Web Based Quiz System Project | 1 Web Based Quiz System | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in register.php through the name parameter.
|
|||||
| CVE-2021-28006 | 1 Web Based Quiz System Project | 1 Web Based Quiz System | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.
|
|||||
| CVE-2021-28002 | 1 Textpattern | 1 Textpattern | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting the 'Articles' page.
|
|||||
| CVE-2021-28001 | 1 Textpattern | 1 Textpattern | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting https://site.com/articles/welcome-to-your-site#comments-head.
|
|||||
| CVE-2021-28000 | 1 Local Services Search Engine Management System Project | 1 Local Services Search Engine Management System | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloads entered into the Name and Address fields.
|
|||||
| CVE-2021-27989 | 1 Appspace | 1 Appspace | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.
|
|||||
| CVE-2021-27969 | 1 Boonex | 1 Dolphin | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.
|
|||||
| CVE-2021-27956 | 1 Zohocorp | 1 Manageengine Adselfservice Plus | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
|
|||||
| CVE-2021-27949 | 1 Mybb | 1 Mybb | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.
|
|||||
| CVE-2021-27945 | 1 Squirro | 1 Squirro | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Squirro Insights Engine was affected by a Reflected Cross-Site Scripting (XSS) vulnerability affecting versions 2.0.0 up to and including 3.2.4. An attacker can use the vulnerability to inject malicious JavaScript code into the application, which will execute within the browser of any user who views the relevant application content. The attacker-supplied code can perform a wide variety of actions, such as stealing victims' session tokens or login credentials, performing arbitrary actions on ...
Show More |
|||||
| CVE-2021-27940 | 1 Openark | 1 Orchestrator | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
resources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter.
|
|||||
| CVE-2021-27938 | 1 Symbiote | 1 Silverstripe Queued Jobs | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.
|
|||||
| CVE-2021-27933 | 1 Pfsense | 1 Pfsense | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
|
|||||
| CVE-2021-27930 | 1 Irislink | 1 Irisnext | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to inject malicious JavaScript in folder/file name within the application in order to grab other users’ sessions or execute malicious code in their browsers (1-click RCE).
|
|||||
| CVE-2021-27914 | 1 Acquia | 1 Mautic | 2024-11-21 | 3.5 LOW | 7.6 HIGH |
|
A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript
|
|||||
| CVE-2021-27912 | 1 Acquia | 1 Mautic | 2024-11-21 | 3.5 LOW | 7.1 HIGH |
|
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inline JS in the title and adding a broken image URL as a remote asset. This can only be leveraged by an authenticated user with permission to create or edit assets.
|
|||||
| CVE-2021-27911 | 1 Acquia | 1 Mautic | 2024-11-21 | 4.3 MEDIUM | 8.3 HIGH |
|
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name and triggered when viewing a contact's details page then clicking on the action drop down and hovering over the Campaigns button. Contact first and last name can be populated from different sources such as UI, API, 3rd party syncing, forms, etc.
|
|||||
| CVE-2021-27910 | 1 Acquia | 1 Mautic | 2024-11-21 | 4.3 MEDIUM | 8.2 HIGH |
|
Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values submitted in the "error" and "error_related_to" parameters of the POST request of the bounce management callback will be permanently stored and executed once the details page of an affected lead is opened by a Mautic user. An attacker with access to the bounce management callback function (identified with the Mailjet webhook, but it is assumed this w ...
Show More |
|||||
| CVE-2021-27909 | 1 Acquia | 1 Mautic | 2024-11-21 | 4.3 MEDIUM | 6.3 MEDIUM |
|
For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker to execute Javascript code. The attacker would be required to convince or trick the target into clicking a password reset URL with the vulnerable parameter utilized.
|
|||||
| CVE-2021-27907 | 1 Apache | 1 Superset | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the context of the user's browser. The javascript code will be automatically executed (Stored XSS) when a legitimate user surfs on the dashboard page. The vulnerability is exploitable creating a “div” section and embedding in it a “svg” element ...
Show More |
|||||
| CVE-2021-27902 | 1 Craftcms | 1 Craft Cms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
|
|||||
| CVE-2021-27889 | 1 Mybb | 1 Mybb | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
|
|||||