Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2019-08-21 CVE-2018-20977 Cross-site Scripting vulnerability in Brainstormforce Schema
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
4.3
2019-08-21 CVE-2018-20970 Cross-site Scripting vulnerability in Bestwebsoft PDF & Print
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
4.3
2019-08-21 CVE-2017-18562 Cross-site Scripting vulnerability in Bestwebsoft Error LOG Viewer
The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
4.3
2019-08-21 CVE-2017-18561 Cross-site Scripting vulnerability in Comments
The embed-comment-images plugin before 0.6 for WordPress has XSS.
4.3
2019-08-21 CVE-2017-18559 Cross-site Scripting vulnerability in Cformsii Project Cformsii
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
network
low complexity
cformsii-project CWE-79
6.1
2019-08-21 CVE-2017-18535 Cross-site Scripting vulnerability in Smokesignal Project Smokesignal
The smokesignal plugin before 1.2.7 for WordPress has XSS.
4.3
2019-08-21 CVE-2017-18525 Cross-site Scripting vulnerability in Megamenu MAX Mega Menu
The megamenu plugin before 2.4 for WordPress has XSS.
network
megamenu CWE-79
4.3
2019-08-21 CVE-2017-18516 Cross-site Scripting vulnerability in Bestwebsoft Linkedin
The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.
4.3
2019-08-21 CVE-2016-10891 Cross-site Scripting vulnerability in Pojo Activity LOG
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
network
low complexity
pojo CWE-79
6.1
2019-08-21 CVE-2016-10890 Cross-site Scripting vulnerability in Pojo Activity LOG
The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
network
low complexity
pojo CWE-79
6.1