Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-45033: cve-request/cve-poc-payload at main · cyb3r-n3rd/cve-request

A cross-site scripting (XSS) vulnerability in Expense Tracker 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Chat text field.

CVE
#xss#vulnerability#web#php#auth
CVE-2020-21219: Prevent ACME output from being interpreted as HTML. Fixes #9888 · pfsense/FreeBSD-ports@a6f443c

Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.

CVE-2020-20589: XSS vulnerability in feehicms v2.0.8 · Issue #45 · liufee/cms

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.

CVE-2021-36572: Cross Site Scripting Vulnerability On Feehi CMS · Issue #58 · liufee/cms

Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page.

CVE-2021-36573: Cross Site Scripting On Image Upload Via File Name · Issue #59 · liufee/cms

File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.

CVE-2022-40373: Unauthorized upload of XML file to execute XSS · Issue #67 · liufee/cms

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.

CVE-2022-40002: Cross Site Scripting Vulnerability On Feehi CMS · Issue #66 · liufee/cms

Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.

CVE-2022-40001: Cross Site Scripting Vulnerability On Feehi CMS · Issue #65 · liufee/cms

Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.

CVE-2022-40000: Cross Site Scripting Vulnerability On Feehi CMS · Issue #64 · liufee/cms

Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Persistent Cross Site Scripting

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from a username persistent cross site scripting vulnerability.