Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-8803 Cross-site Scripting vulnerability in Madfishdigital Bulk Noindex & Nofollow Toolkit
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15.
network
low complexity
madfishdigital CWE-79
6.1
2024-09-25 CVE-2023-51157 Cross-site Scripting vulnerability in Zkteco Wdms 5.1.3
Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.
network
low complexity
zkteco CWE-79
5.4
2024-09-25 CVE-2024-46655 Cross-site Scripting vulnerability in Ellevo 6.2.0.38160
A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL.
network
low complexity
ellevo CWE-79
6.1
2024-09-25 CVE-2024-20475 Cross-site Scripting vulnerability in Cisco Catalyst Sd-Wan Manager
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input.
network
low complexity
cisco CWE-79
5.4
2024-09-25 CVE-2024-45613 Cross-site Scripting vulnerability in Ckeditor Ckeditor5
CKEditor 5 is a JavaScript rich-text editor.
network
low complexity
ckeditor CWE-79
6.1
2024-09-25 CVE-2024-8546 Cross-site Scripting vulnerability in Wpmet Elementskit Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2024-09-25 CVE-2024-8858 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping.
network
low complexity
livemeshelementor CWE-79
5.4
2024-09-25 CVE-2024-9169 The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
5.5
2024-09-25 CVE-2024-47303 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through 8.5.
network
low complexity
livemeshelementor CWE-79
5.4
2024-09-25 CVE-2024-3866 Cross-site Scripting vulnerability in Ninjaforms Ninja Forms
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping.
network
low complexity
ninjaforms CWE-79
6.1