Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-02-29 CVE-2024-22936 Cross-site Scripting vulnerability in Manuelaldape Parents & Student Portal 3053
Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
network
low complexity
manuelaldape CWE-79
6.1
2024-02-29 CVE-2024-25712 Cross-site Scripting vulnerability in Http-Swagger Project Http-Swagger
http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a GET request.
network
low complexity
http-swagger-project CWE-79
6.1
2024-02-29 CVE-2024-25831 Cross-site Scripting vulnerability in F-Logic Datacube3 1.0
F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization.
network
low complexity
f-logic CWE-79
5.4
2024-02-29 CVE-2024-27517 Cross-site Scripting vulnerability in Webasyst 2.9.9
Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code after gaining blog permissions.
network
low complexity
webasyst CWE-79
5.4
2024-02-29 CVE-2024-0438 Cross-site Scripting vulnerability in Leevio Happy Addons for Elementor
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping.
network
low complexity
leevio CWE-79
5.4
2024-02-29 CVE-2024-0506 Cross-site Scripting vulnerability in Elementor Website Builder
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in the get_image_alt function in all versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping.
network
low complexity
elementor CWE-79
5.4
2024-02-29 CVE-2024-0602 Cross-site Scripting vulnerability in Yarpp YET Another Related Posts Plugin
The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping.
network
high complexity
yarpp CWE-79
4.0
2024-02-29 CVE-2024-0604 Cross-site Scripting vulnerability in Fooplugins Foogallery
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping.
network
low complexity
fooplugins CWE-79
4.8
2024-02-29 CVE-2024-0656 Cross-site Scripting vulnerability in Wpexperts Password Protected 2.6.2
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Captcha Site Key in all versions up to, and including, 2.6.6 due to insufficient input sanitization and output escaping.
network
low complexity
wpexperts CWE-79
4.8
2024-02-29 CVE-2024-0792 Cross-site Scripting vulnerability in Getshortcodes Shortcodes Ultimate
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping on RSS feed content.
network
low complexity
getshortcodes CWE-79
5.4