Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-0938: Stored XSS via file upload in showdoc

Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE
#xss#web#git
CVE-2022-0341

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.

CVE-2022-0937: file upload bug · star7th/showdoc@42c0d98

Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2021-46709: XSS vulnerability

phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number).

CVE-2021-45888

An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only possible for users who have the role Configuration Administrator or Administrator.

CVE-2021-45889

An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databaseTab.jsp or private/index.jsp?activation/activationMainTab.jsp or private/index.jsp?communication/serverTab.jsp or private/index.jsp?emailNotification/notificationTab.jsp.

CVE-2022-0930: make plupload only allowed files · microweber/microweber@33eb4cc

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0929: Update build-and-upload.yml · microweber/microweber@de6d17b

XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-0926: Update Files.php · microweber/microweber@89200cf

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0880: file upload bug · star7th/showdoc@818d7fe

Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.