Search Results (42958 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-45986 2 Online Voting System Project, Projectworlds 2 Online Voting System, Online Voting System Project 2025-05-06 5.4 Medium
A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.
CVE-2023-6081 1 Chartjs Project 1 Chartjs 2025-05-06 5.4 Medium
The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2022-3420 1 Official Integration For Billingo Project 1 Official Integration For Billingo 2025-05-06 4.8 Medium
The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.
CVE-2022-3408 1 Redlettuce 1 Wp Word Count 2025-05-06 4.8 Medium
The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2024-45967 1 Pagekit 1 Pagekit 2025-05-06 4.7 Medium
Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
CVE-2024-28150 1 Jenkins 1 Html Publisher 2025-05-06 4.7 Medium
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2024-28149 2 Jenkins, Redhat 2 Html Publisher, Ocp Tools 2025-05-06 6.5 Medium
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
CVE-2022-40290 1 Phppointofsale 1 Php Point Of Sale 2025-05-06 6.1 Medium
The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode generation functionality, allowing attackers to generate an unsafe link that could compromise users.
CVE-2022-40289 1 Phppointofsale 1 Php Point Of Sale 2025-05-06 9 Critical
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.
CVE-2022-40288 1 Phppointofsale 1 Php Point Of Sale 2025-05-06 9 Critical
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile.
CVE-2022-40287 1 Phppointofsale 1 Php Point Of Sale 2025-05-06 9 Critical
The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account.
CVE-2022-3441 1 Rockcontent 1 Rock Convert 2025-05-06 4.8 Medium
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3440 1 Rockcontent 1 Rock Convert 2025-05-06 6.1 Medium
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting
CVE-2018-19904 1 Xsltcms.org Project 1 Xsltcms.org 2025-05-06 6.1 Medium
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.
CVE-2024-10679 1 Expresstech 1 Quiz And Survey Master 2025-05-06 6.1 Medium
The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2025-1452 1 Favoriteposts 1 Favorites 2025-05-06 3.5 Low
The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-2304 1 Favoriteposts 1 Favorites 2025-05-06 6.4 Medium
The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-12682 1 Brijeshk89 1 Smart Maintenance Mode 2025-05-06 6.1 Medium
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2022-40739 1 Ragic 1 Ragic 2025-05-06 5.4 Medium
Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-Site Scripting) attack.
CVE-2022-39020 1 Schoolbox 1 Schoolbox 2025-05-06 7.6 High
Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.