Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-07-11 CVE-2024-6256 Cross-site Scripting vulnerability in Smashballoon Feeds for Youtube
The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
smashballoon CWE-79
5.4
2024-07-11 CVE-2024-4655 Cross-site Scripting vulnerability in Dotcamp Ultimate Blocks
The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
network
low complexity
dotcamp CWE-79
5.4
2024-07-11 CVE-2024-5444 Cross-site Scripting vulnerability in Mark8Barnes Bible Text 0.2
The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
network
low complexity
mark8barnes CWE-79
5.4
2024-07-11 CVE-2024-6025 Cross-site Scripting vulnerability in Expresstech Quiz and Survey Master
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks
network
low complexity
expresstech CWE-79
5.4
2024-07-11 CVE-2024-6026 Cross-site Scripting vulnerability in 10Web Slider
The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56's options) and the ability to add images (Editor+) to perform Stored Cross-Site Scripting attacks
network
low complexity
10web CWE-79
5.4
2024-07-11 CVE-2024-6138 Cross-site Scripting vulnerability in Ays-Pro Secure Copy Content Protection and Content Locking
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
ays-pro CWE-79
4.8
2024-07-10 CVE-2024-38354 Cross-site Scripting vulnerability in Hackmd Codimd
CodiMD allows realtime collaborative markdown notes on all platforms.
network
low complexity
hackmd CWE-79
6.1
2024-07-10 CVE-2024-27095 Cross-site Scripting vulnerability in Decidim
Decidim is a participatory democracy framework.
network
low complexity
decidim CWE-79
4.8
2024-07-10 CVE-2023-35006 Cross-site Scripting vulnerability in IBM Security Qradar EDR 3.12
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
5.4
2024-07-10 CVE-2024-5664 Cross-site Scripting vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
sonaar CWE-79
5.4