Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-04-06 CVE-2024-0837 Cross-site Scripting vulnerability in Bdthemes Element Pack
The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping.
network
low complexity
bdthemes CWE-79
5.4
2024-04-06 CVE-2024-1428 Cross-site Scripting vulnerability in Bdthemes Element Pack
The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping.
network
low complexity
bdthemes CWE-79
5.4
2024-04-06 CVE-2024-2471 Cross-site Scripting vulnerability in Fooplugins Foogallery
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping.
network
low complexity
fooplugins CWE-79
5.4
2024-04-06 CVE-2024-3245 Cross-site Scripting vulnerability in Wpdeveloper Embedpress
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Youtube block in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpdeveloper CWE-79
5.4
2024-04-05 CVE-2024-2380 Cross-site Scripting vulnerability in Checkmk 2.3.0
Stored XSS in graph rendering in Checkmk <2.3.0b4.
network
low complexity
checkmk CWE-79
5.4
2024-04-04 CVE-2024-29049 Cross-site Scripting vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
network
high complexity
microsoft CWE-79
4.7
2024-04-04 CVE-2024-25690 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.
network
low complexity
esri CWE-79
4.7
2024-04-04 CVE-2024-25706 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website.
network
low complexity
esri CWE-79
6.1
2024-04-04 CVE-2024-25709 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS versions 10.8.1 – 1121 that may allow a remote, authenticated attacker to create a crafted link that can be saved as a new location when moving an existing item which will potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
4.8
2024-04-04 CVE-2024-2919 Cross-site Scripting vulnerability in Kadencewp Gutenberg Blocks With AI
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CountUp Widget in all versions up to, and including, 3.2.31 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
kadencewp CWE-79
5.4