Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-10-04 CVE-2024-25707 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript code in the their own browser (Self XSS).
network
low complexity
esri CWE-79
4.8
2024-10-04 CVE-2024-38038 Cross-site Scripting vulnerability in Esri Portal for Arcgis 10.7.1/10.8.1/10.9.1
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
6.1
2024-10-04 CVE-2024-38039 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).
network
low complexity
esri CWE-79
5.4
2024-10-04 CVE-2024-8499 Cross-site Scripting vulnerability in Themehigh Checkout Field Editor
The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping.
network
low complexity
themehigh CWE-79
6.1
2024-10-04 CVE-2024-9071 Cross-site Scripting vulnerability in Sigmadevs Easy Demo Importer
The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping.
network
low complexity
sigmadevs CWE-79
5.4
2024-10-04 CVE-2024-9271 Cross-site Scripting vulnerability in Remilia Re:Wp
The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping.
network
low complexity
remilia CWE-79
5.4
2024-10-04 CVE-2024-9306 Cross-site Scripting vulnerability in Wpbookingcalendar WP Booking Calendar
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping.
network
low complexity
wpbookingcalendar CWE-79
4.8
2024-10-04 CVE-2024-9435 Cross-site Scripting vulnerability in Plainware Shiftcontroller
The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to insufficient input sanitization and output escaping.
network
low complexity
plainware CWE-79
6.1
2024-10-04 CVE-2024-47854 Cross-site Scripting vulnerability in Veritas Data Insight
An XSS vulnerability was discovered in Veritas Data Insight before 7.1.
network
low complexity
veritas CWE-79
6.1
2024-10-04 CVE-2024-8804 Cross-site Scripting vulnerability in Davidartiss Code Embed
The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions on who can utilize the functionality.
network
low complexity
davidartiss CWE-79
5.4