Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-05-29 CVE-2024-36367 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
network
low complexity
jetbrains CWE-79
6.1
2024-05-29 CVE-2024-36368 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36369 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36370 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36371 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36372 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
network
low complexity
jetbrains CWE-79
6.1
2024-05-29 CVE-2024-36373 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36374 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-27313 Cross-site Scripting vulnerability in Zohocorp Manageengine Pam360 6.6
Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability.
network
low complexity
zohocorp CWE-79
4.6
2024-05-24 CVE-2024-4366 Cross-site Scripting vulnerability in Brainstormforce Spectra
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping.
network
low complexity
brainstormforce CWE-79
5.4