Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-10-28 CVE-2024-50576 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
network
low complexity
jetbrains CWE-79
5.4
2024-10-28 CVE-2024-50577 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
network
low complexity
jetbrains CWE-79
5.4
2024-10-28 CVE-2024-50578 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
network
low complexity
jetbrains CWE-79
5.4
2024-10-28 CVE-2024-50579 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
network
low complexity
jetbrains CWE-79
6.1
2024-10-28 CVE-2024-50580 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
network
low complexity
jetbrains CWE-79
5.4
2024-10-28 CVE-2024-50581 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
network
low complexity
jetbrains CWE-79
5.4
2024-10-28 CVE-2024-50582 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
network
low complexity
jetbrains CWE-79
5.4
2024-10-28 CVE-2024-10433 Cross-site Scripting vulnerability in Projectworlds Simple Web-Based Chat Application 1.0
A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic.
network
low complexity
projectworlds CWE-79
6.1
2024-10-27 CVE-2024-10419 Cross-site Scripting vulnerability in Fabianros Blood Bank Management System 1.0
A vulnerability was found in code-projects Blood Bank Management System 1.0.
network
low complexity
fabianros CWE-79
6.1
2024-10-27 CVE-2024-10414 Cross-site Scripting vulnerability in PHPgurukul Vehicle Record System 1.0
A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0.
network
low complexity
phpgurukul CWE-79
4.8