Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

Bug Bounty Radar // The latest bug bounty programs for August 2022

New web targets for the discerning hacker

PortSwigger
#sql#xss#csrf#vulnerability#web#ios#mac#apple#google#microsoft#git#rce#ssrf#pdf
GHSA-25q6-m425-9fqr: Feehi CMS Cross-site Scripting

A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.

CVE-2022-34580: bug_report/XSS-1.md at main · wencongzhao/bug_report

Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the address parameter at ip/school/index.php.

CVE-2022-29360: RainLoop Webmail - Emails at Risk due to Code Flaw

The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.

CVE-2022-34578: Open Source Point of Sale v3.3.7— File Upload Cross-Site Scripting

Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

CVE-2016-2138: Block XSS in wget commands (file links) · ikoniaris/kippo-graph@e6587ec

In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in xss_clean() in class/KippoInput.class.php.

CVE-2022-35882: WordPress GS Testimonial Slider plugin <= 1.9.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability - Patchstack

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial Slider plugin <= 1.9.1 at WordPress.

CVE-2022-1948

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.