Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-38295: XSS Vulnerability exists in Cuppa CMS in Users · Issue #34 · CuppaCMS/CuppaCMS

Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.

CVE
#xss#vulnerability#web#git
CVE-2022-38291: XSS in search bar · Issue #156 · slims/slims9_bulian

SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.

ETAP Safety Manager 1.0.0.32 Cross Site Scripting

ETAP Safety Manager version 1.0.0.32 suffers from a cross site scripting vulnerability.

CVE-2022-36254: Public Reference for CVE-2022-36254

Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".

CVE-2022-38972: Movable Type plugin A-Form vulnerable to cross-site scripting

Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3.9.1 (for Movable Type 6 Series) allows a remote unauthenticated attacker to inject an arbitrary script.

CVE-2022-37796: CVE_demo/Simple Online Book Store-XSS.md at main · anx0ing/CVE_demo

In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS).

ETAP Safety Manager 1.0.0.32 Remote Unauthenticated Reflected XSS

Input passed to the GET parameter 'action' is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.

GHSA-462r-wxvm-jvxh: Markdown-Nice v1.8.22 vulnerable to Cross-site Scripting

A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.

CVE-2022-38639: markdown preview executes the xss Vulnerability · Issue #327 · mdnice/markdown-nice

A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.