Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-39527: New possible XSS injection through Validate::isCleanHTML method

PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

CVE
#xss#vulnerability#web#git
CVE-2023-38045: Admiror Gallery - Joomla! Extension Directory

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

Debian Security Advisory 5470-1

Debian Linux Security Advisory 5470-1 - Several vulnerabilities were discovered in python-werkzeug, a collection of utilities for WSGI applications.

Social-Commerce 3.1.6 Cross Site Scripting

Social-Commerce version 3.1.6 suffers from a cross site scripting vulnerability.

mooSocial 3.1.8 Cross Site Scripting

mooSocial version 3.1.8 suffers from a cross site scripting vulnerability.

Database Compilation 1.2 Cross Site Scripting

Database Compilation CMS version 1.2 suffers from a cross site scripting vulnerability.

Cvanav-DAW CMS 0.1 Cross Site Scripting

Cvanav-DAW CMS version 0.1 suffers from a cross site scripting vulnerability.

CMS BMGI International 4.0 Cross Site Scripting

CMS BMGI International version 4.0 suffers from a cross site scripting vulnerability.

CVE-2023-0604

The WP Food Manager WordPress plugin before 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)