Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-24225 | 1 Elbtide | 1 Advanced Booking Calendar | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue
|
|||||
| CVE-2021-24214 | 1 Daggerhartlab | 1 Openid Connect Generic Client | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.
|
|||||
| CVE-2021-24213 | 1 Givewp | 1 Givewp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.
|
|||||
| CVE-2021-24208 | 1 Themeum | 1 Wp Page Builder | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into pages via the “Raw HTML” widget and the “Custom HTML” widgets (though the custom HTML widget requires sending a crafted request - it appears that this widget uses some form of client side validation but not server side validation), all of which are added via the “page_builder_data” parameter when performing the “wppb_page_save” AJAX action. It is als ...
Show More |
|||||
| CVE-2021-24206 | 1 Elementor | 1 Website Builder | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is view ...
Show More |
|||||
| CVE-2021-24205 | 1 Elementor | 1 Website Builder | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed ...
Show More |
|||||
| CVE-2021-24204 | 1 Elementor | 1 Website Builder | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page ...
Show More |
|||||
| CVE-2021-24203 | 1 Elementor | 1 Website Builder | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘text’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.
|
|||||
| CVE-2021-24202 | 1 Elementor | 1 Website Builder | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘title’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.
|
|||||
| CVE-2021-24201 | 1 Elementor | 1 Website Builder | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or p ...
Show More |
|||||
| CVE-2021-24196 | 1 Cm-wp | 1 Social Slider Widget | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
|
|||||
| CVE-2021-24187 | 1 Clogica | 1 Seo Redirection | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.
|
|||||
| CVE-2021-24180 | 1 Never5 | 1 Related Posts | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.
|
|||||
| CVE-2021-24176 | 1 Jh 404 Logger Project | 1 Jh 404 Logger | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.
|
|||||
| CVE-2021-24169 | 1 Algolplus | 1 Advanced Order Export For Woocommerce | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.
|
|||||
| CVE-2021-24168 | 1 Easy Contact Form Pro Project | 1 Easy Contact Form Pro | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator.
|
|||||
| CVE-2021-24157 | 1 Themeisle | 1 Orbit Fox | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious.
|
|||||
| CVE-2021-24156 | 1 Testimonial Rotator Project | 1 Testimonial Rotator | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
|
|||||
| CVE-2021-24153 | 1 Yoast | 1 Yoast Seo | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.
|
|||||
| CVE-2021-24152 | 1 Sygnoos | 1 Popup Builder | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
|
|||||
| CVE-2021-24147 | 1 Webnus | 1 Modern Events Calendar Lite | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_comment field (Notes on time) when adding/editing an event, allowing users with privilege as low as author to add events with a Cross-Site Scripting payload in them, which will be triggered in the frontend when viewing the event.
|
|||||
| CVE-2021-24136 | 1 Axelerant | 1 Testimonials Widget | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL
|
|||||
| CVE-2021-24135 | 1 Gowebsolutions | 1 Wp Customer Reviews | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.
|
|||||
| CVE-2021-24134 | 1 Constantcontact | 1 Constant Contact Forms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.
|
|||||
| CVE-2021-24129 | 1 Themify | 1 Portfolio Post | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged users (Contributor+) to inject arbitrary JavaScript code or HTML in posts where the Themify Custom Panel is embedded, which could lead to privilege escalation.
|
|||||
| CVE-2021-24128 | 1 Wpdarko | 1 Team Members | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.
|
|||||
| CVE-2021-24127 | 1 Caseproof | 1 Thirstyaffiliates Affiliate Link Manager | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.
|
|||||
| CVE-2021-24126 | 1 Enviragallery | 1 Envira Gallery | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.
|
|||||
| CVE-2021-24124 | 1 Terryl | 1 Wp Shieldon | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is shown could lead to privileged escalation.
|
|||||
| CVE-2021-24021 | 1 Fortinet | 1 Fortianalyzer | 2024-11-21 | 3.5 LOW | 4.3 MEDIUM |
|
An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below and 6.0.10 and below may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the column settings of Logview in FortiAnalyzer, should the attacker be able to obtain that POST request, via other, hypothetical attacks.
|
|||||
| CVE-2021-24014 | 1 Fortinet | 1 Fortisandbox | 2024-11-21 | 4.3 MEDIUM | 5.4 MEDIUM |
|
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.
|
|||||
| CVE-2021-23959 | 1 Mozilla | 1 Firefox | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
|
|||||
| CVE-2021-23936 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
OX App Suite through 7.10.4 allows XSS via the subject of a task.
|
|||||
| CVE-2021-23935 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.
|
|||||
| CVE-2021-23934 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.
|
|||||
| CVE-2021-23933 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
|
|||||
| CVE-2021-23932 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.
|
|||||
| CVE-2021-23931 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
OX App Suite through 7.10.4 allows XSS via an inline binary file.
|
|||||
| CVE-2021-23930 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.
|
|||||
| CVE-2021-23929 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI.
|
|||||