Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-11-05 CVE-2023-34445 Cross-site Scripting vulnerability in Combodo Itop
Combodo iTop is a simple, web based IT Service Management tool.
network
low complexity
combodo CWE-79
6.1
2024-11-05 CVE-2024-31448 Cross-site Scripting vulnerability in Combodo Itop
Combodo iTop is a simple, web based IT Service Management tool.
network
low complexity
combodo CWE-79
6.1
2024-11-04 CVE-2024-10768 Cross-site Scripting vulnerability in PHPgurukul Online Shopping Portal 2.0
A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0.
network
low complexity
phpgurukul CWE-79
5.4
2024-11-04 CVE-2024-51677 Cross-site Scripting vulnerability in Webberzone Knowledge Base
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebberZone Knowledge Base allows Stored XSS.This issue affects Knowledge Base: from n/a through 2.2.0.
network
low complexity
webberzone CWE-79
5.4
2024-11-04 CVE-2024-51678 Cross-site Scripting vulnerability in Timelord ELO Rating Shortcode
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode allows Stored XSS.This issue affects Elo Rating Shortcode: from n/a through 1.0.3.
network
low complexity
timelord CWE-79
5.4
2024-11-04 CVE-2024-51680 Cross-site Scripting vulnerability in Crestaproject Cresta Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrestaProject – Rizzo Andrea Cresta Addons for Elementor allows Stored XSS.This issue affects Cresta Addons for Elementor: from n/a through 1.0.9.
network
low complexity
crestaproject CWE-79
5.4
2024-11-04 CVE-2024-51681 Cross-site Scripting vulnerability in Coderevolution WP Pocket Urls 1.0.0/1.0.2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.
network
low complexity
coderevolution CWE-79
5.4
2024-11-04 CVE-2024-51682 Cross-site Scripting vulnerability in Hasthemes HT Builder
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor allows Stored XSS.This issue affects HT Builder – WordPress Theme Builder for Elementor: from n/a through 1.3.0.
network
low complexity
hasthemes CWE-79
5.4
2024-11-04 CVE-2024-51683 Cross-site Scripting vulnerability in Migaweb Custom Post Type Templates for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a through 1.10.1.
network
low complexity
migaweb CWE-79
5.4
2024-11-04 CVE-2024-51685 Cross-site Scripting vulnerability in Migaweb Accordion Title for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Accordion title for Elementor allows Stored XSS.This issue affects Accordion title for Elementor: from n/a through 1.2.1.
network
low complexity
migaweb CWE-79
4.8