Search Results (42958 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-12407 2025-01-13 6.1 Medium
The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pushnotificationid' parameter in all versions up to, and including, 2.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2023-1869 1 Plugin 1 Yourchannel 2025-01-13 5.5 Medium
The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVE-2023-29101 1 Muffingroup 1 Betheme 2025-01-13 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Muffingroup Betheme theme <= 26.7.5 versions.
CVE-2023-2498 1 Granthweb 1 Go Pricing 2025-01-13 6.4 Medium
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.19 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-2436 1 Blog-in-blog Project 1 Blog-in-blog 2025-01-13 5.5 Medium
The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-1661 1 Display Post Meta\, Term Meta\, Comment Meta\, And User Meta Project 1 Display Post Meta\, Term Meta\, Comment Meta\, And User Meta 2025-01-13 6.4 Medium
The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post metadata in versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2022-42462 1 Ip Blacklist Cloud Project 1 Ip Blacklist Cloud 2025-01-13 4.8 Medium
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
CVE-2022-40697 1 3commarketing 1 3com-asesor-de-cookies 2025-01-13 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 3com – Asesor de Cookies para normativa española plugin <= 3.4.3 versions.
CVE-2023-22721 1 Oi Yandex.maps Project 1 Oi Yandex.maps 2025-01-13 6.5 Medium
Auth. Stored Cross-Site Scripting (XSS) in Oi Yandex.Maps for WordPress <= 3.2.7 versions.
CVE-2023-23687 1 Youtube Shortcode Project 1 Youtube Shortcode 2025-01-13 6.5 Medium
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions.
CVE-2022-29416 1 Afterpay 1 Afterpay Gateway For Woocommerce 2025-01-13 4.7 Medium
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.
CVE-2022-37402 1 Afsanalytics 1 Afs Analytics 2025-01-13 4.8 Medium
Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions.
CVE-2022-38971 1 Themekraft 1 Post Form Registration Form Profile Form For User Profiles And Content Forms 2025-01-13 4.7 Medium
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
CVE-2022-40699 1 Yasr - Yet Another Stars Rating Project 1 Yasr - Yet Another Stars Rating 2025-01-13 5.4 Medium
Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions.
CVE-2022-41554 1 Slideshow Se Project 1 Slideshow Se 2025-01-13 4.8 Medium
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
CVE-2022-43461 1 Slideshow Se Project 1 Slideshow Se 2025-01-13 4.8 Medium
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
CVE-2022-45817 1 Gc Testimonials Project 1 Gc Testimonials 2025-01-13 5.4 Medium
Cross-Site Scripting (XSS) vulnerability in Erin Garscadden GC Testimonials plugin <= 1.3.2 versions.
CVE-2023-25795 1 Wp-master 1 Feed Changer \& Remover 2025-01-13 5.9 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions.
CVE-2023-25794 1 Nooz Project 1 Nooz 2025-01-13 5.9 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0 versions.
CVE-2025-0397 2025-01-13 3.5 Low
A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown function of the file /;/admin/role/edit. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.