Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-10-27 CVE-2024-10412 Cross-site Scripting vulnerability in Poco-Z Guns-Medial 1.0
A vulnerability was found in Poco-z Guns-Medical 1.0.
network
low complexity
poco-z CWE-79
5.4
2024-10-26 CVE-2024-10117 The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate shortcode in all versions up to, and including, 2.1.11 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-9642 The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-9853 The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-9456 The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.0 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-8870 The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.6.
network
low complexity
CWE-79
6.1
2024-10-26 CVE-2024-10091 Cross-site Scripting vulnerability in Wpmet Elements KIT Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2024-10-26 CVE-2024-9454 The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.11 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-9462 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions up to, and including, 5.4.6 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
5.5
2024-10-26 CVE-2024-9613 The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'userId' and 'publishId' parameters in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1