Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-2320

The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE
#xss#google#wordpress
AppleZeed CMS 2.0 SQL Injection

AppleZeed CMS version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Car Rental Script 1.8 Cross Site Scripting

Car Rental Script version 1.8 suffers from a cross site scripting vulnerability.

Aathesh Soft CMS 0.3.0 Cross Site Scripting

Aathesh Soft CMS version 0.3.0 suffers from a cross site scripting vulnerability.

Ariadna CMS 0.3 Cross Site Scripting

Ariadna CMS version 0.3 suffers from a cross site scripting vulnerability.

CVE-2020-22153: Code execution in navigation/upload · Issue #553 · daylightstudio/FUEL-CMS

File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.

CVE-2020-22152: XSS in pages · Issue #552 · daylightstudio/FUEL-CMS

Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function.

CVE-2023-36223

Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.

CVE-2023-36222: bbs-go 存储式跨站脚本漏洞1 · Issue #206 · mlogclub/bbs-go

Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the comment parameter in the article function.