Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-07-15 CVE-2024-6074 Cross-site Scripting vulnerability in Tipsandtricks-Hq WP Estore
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
tipsandtricks-hq CWE-79
6.1
2024-07-15 CVE-2024-6076 Cross-site Scripting vulnerability in Tipsandtricks-Hq WP Estore
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
tipsandtricks-hq CWE-79
6.1
2024-07-15 CVE-2024-39735 Cross-site Scripting vulnerability in IBM Datacap and Datacap Navigator
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-07-12 CVE-2024-6495 Cross-site Scripting vulnerability in Leap13 Premium Addons for Elementor
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text widget in all versions up to, and including, 4.10.36 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
leap13 CWE-79
5.4
2024-07-12 CVE-2024-2430 Cross-site Scripting vulnerability in Matteoenna Website Content in Page or Post
The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
network
low complexity
matteoenna CWE-79
5.4
2024-07-12 CVE-2024-2640 Cross-site Scripting vulnerability in Kibokolabs Watu Quiz
The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
network
low complexity
kibokolabs CWE-79
5.4
2024-07-12 CVE-2024-4753 Cross-site Scripting vulnerability in Wpexperts WP Secure Maintenance
The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
wpexperts CWE-79
4.8
2024-07-12 CVE-2024-5626 Cross-site Scripting vulnerability in Data443 Inline Related Posts
The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
data443 CWE-79
6.1
2024-07-12 CVE-2024-5811 Cross-site Scripting vulnerability in Quantumcloud Simple Video Directory
The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
quantumcloud CWE-79
5.4
2024-07-11 CVE-2024-6484 Cross-site Scripting vulnerability in Getbootstrap Bootstrap
A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks.
network
low complexity
getbootstrap CWE-79
6.1