Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-10-01 CVE-2024-9274 The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.4 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-01 CVE-2024-8107 Cross-site Scripting vulnerability in Themepunch Slider Revolution
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping.
network
low complexity
themepunch CWE-79
5.4
2024-10-01 CVE-2024-47396 Cross-site Scripting vulnerability in Moveaddons Move Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.3.
network
low complexity
moveaddons CWE-79
5.4
2024-09-30 CVE-2024-45073 Cross-site Scripting vulnerability in IBM Websphere Application Server 8.5/9.0
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
4.8
2024-09-30 CVE-2024-9158 Cross-site Scripting vulnerability in Tenable Nessus Network Monitor
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
local
low complexity
tenable CWE-79
4.6
2024-09-30 CVE-2024-47067 Cross-site Scripting vulnerability in Alist Project Alist
AList is a file list program that supports multiple storages.
network
low complexity
alist-project CWE-79
6.1
2024-09-30 CVE-2024-47063 Cross-site Scripting vulnerability in Cvat Computer Vision Annotation Tool
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision.
network
low complexity
cvat CWE-79
6.1
2024-09-30 CVE-2024-8457 Cross-site Scripting vulnerability in Planet Gs-4210-24P2S Firmware and Gs-4210-24Pl4C Firmware
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
network
low complexity
planet CWE-79
4.8
2024-09-30 CVE-2024-3635 Cross-site Scripting vulnerability in Radiustheme the Post Grid
The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
radiustheme CWE-79
4.8
2024-09-30 CVE-2024-8239 Cross-site Scripting vulnerability in Squirrly Starbox
The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
network
low complexity
squirrly CWE-79
5.4