Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-44743: WordPress Jobs for WordPress plugin <= 2.5.11.2 - Auth. Stored Cross-Site Scripting (XSS) vulnerability - Patchstack

Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versions.

CVE
#xss#vulnerability#web#wordpress#auth
CVE-2022-44594: WordPress All in One Time Clock Lite plugin <= 1.3.320 - Auth. Stored Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Codebangers All in One Time Clock Lite plugin <= 1.3.320 versions.

CVE-2023-24386: WordPress AI Contact Us Form plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Karishma Arora AI Contact Us Form plugin <= 1.0 versions.

CVE-2023-24404: WordPress Marketing Performance plugin <= 2.0.0 - Cross Site Scripting (XSS) vulnerability - Patchstack

Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions.

CVE-2022-44631: WordPress 1app Business Forms plugin <= 1.0.0 - Auth. Stored Cross-Site Scripting (XSS) vulnerability - Patchstack

Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in 1app Technologies, Inc 1app Business Forms plugin <= 1.0.0 versions.

CVE-2022-44582: WordPress Apptivo Business Site CRM plugin <= 3.0.12 - Auth. Stored Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <= 3.0.12 versions.

GHSA-ch5w-2994-6h82: Cross-site Scripting in thorsten/phpmyfaq

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-1875: fix: added missing conversion to HTML entities · thorsten/phpMyFAQ@dcf7dd4

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

GHSA-mj9r-fpv3-rgfx: Shopware vulnerable to cross-site scripting (XSS)

Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2022-48150: GitHub - sahilop123/-CVE-2022-48150: I Found the reflected xss vulnerability in shopware 5 .for more details check my poc video

Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.