Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-07-19 CVE-2024-39457 Cross-site Scripting vulnerability in Cybozu Garoon 6.0.0/6.0.1
Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview.
network
low complexity
cybozu CWE-79
5.4
2024-07-18 CVE-2024-39682 Cross-site Scripting vulnerability in Boxystudio Cooked
Cooked is a recipe plugin for WordPress.
network
low complexity
boxystudio CWE-79
5.4
2024-07-17 CVE-2023-43971 Cross-site Scripting vulnerability in Lizhipay Acg-Faka 1.1.7
Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode parameter in Index.php.
network
low complexity
lizhipay CWE-79
6.1
2024-07-17 CVE-2024-39124 Cross-site Scripting vulnerability in Roundup-Tracker Roundup
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
network
low complexity
roundup-tracker CWE-79
5.4
2024-07-17 CVE-2024-39125 Cross-site Scripting vulnerability in Roundup-Tracker Roundup
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
network
low complexity
roundup-tracker CWE-79
5.4
2024-07-17 CVE-2024-39126 Cross-site Scripting vulnerability in Roundup-Tracker Roundup
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
network
low complexity
roundup-tracker CWE-79
5.4
2024-07-17 CVE-2024-39863 Cross-site Scripting vulnerability in Apache Airflow
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider.
network
low complexity
apache CWE-79
5.4
2024-07-17 CVE-2024-5582 Cross-site Scripting vulnerability in Magazine3 Schema & Structured Data for WP & AMP
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the Q&A Block widget in all versions up to, and including, 1.33 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
magazine3 CWE-79
5.4
2024-07-17 CVE-2024-5251 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_pricing shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
brainstormforce CWE-79
5.4
2024-07-17 CVE-2024-5252 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
brainstormforce CWE-79
5.4