Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2021-42648: Cross Site Scripting(XSS)vulnerability in code-server · Issue #4355 · coder/code-server

Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.

CVE
#xss#vulnerability#git
CVE-2022-30057

Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.

CVE-2021-28290: XSS issue in Client Secrets and Api Resource Secrets · Issue #813 · skoruba/IdentityServer4.Admin

A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.

CVE-2021-28290: XSS issue in Client Secrets and Api Resource Secrets · Issue #813 · skoruba/IdentityServer4.Admin

A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.

CVE-2021-31330: Review Board 4.0 RC 2 Release Notes

A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.

CVE-2021-31330: Review Board 4.0 RC 2 Release Notes

A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.

WordPress Blue Admin 21.06.01 Cross Site Request Forgery

WordPress Blue Admin plugin version 21.06.01 suffers from a cross site request forgery vulnerability.

CVE-2022-23137: Security Bulletin Details

ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.

CVE-2022-23137: Security Bulletin Details

ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.

CVE-2021-39059: Security Bulletin: IBM Engineering Lifecycle Management is vulnerable to Cross-site Scripting (XSS). (CVE-2021-39059)

IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214619.