Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-05-29 CVE-2024-36373 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36374 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-27313 Cross-site Scripting vulnerability in Zohocorp Manageengine Pam360 6.6
Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability.
network
low complexity
zohocorp CWE-79
4.6
2024-05-24 CVE-2024-4366 Cross-site Scripting vulnerability in Brainstormforce Spectra
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping.
network
low complexity
brainstormforce CWE-79
5.4
2024-05-24 CVE-2024-4484 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘xai_username’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping.
network
low complexity
posimyth CWE-79
5.4
2024-05-24 CVE-2024-4485 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_custom_attributes’ parameter in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping.
network
low complexity
posimyth CWE-79
5.4
2024-05-24 CVE-2024-3718 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
posimyth CWE-79
5.4
2024-05-24 CVE-2024-2618 Cross-site Scripting vulnerability in Brainstormforce Elementor Header & Footer Builder
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping.
network
low complexity
brainstormforce CWE-79
5.4
2024-05-24 CVE-2024-2784 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card widget in all versions up to, and including, 5.5.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
posimyth CWE-79
5.4
2024-05-24 CVE-2024-3557 Cross-site Scripting vulnerability in Codecabin WP GO Maps
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
codecabin CWE-79
5.4