Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-01-27 CVE-2024-0824 Cross-site Scripting vulnerability in Devscred Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping.
network
low complexity
devscred CWE-79
5.4
2024-01-27 CVE-2023-6497 Cross-site Scripting vulnerability in Tipsandtricks-Hq Wordpress Simple Paypal Shopping Cart
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to and including 4.7.1 due to insufficient input sanitization and output escaping.
network
low complexity
tipsandtricks-hq CWE-79
4.8
2024-01-27 CVE-2024-0664 Cross-site Scripting vulnerability in Mekshq Meks Smart Social Widget
The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social Widget in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping.
network
low complexity
mekshq CWE-79
4.8
2024-01-26 CVE-2024-20305 Cross-site Scripting vulnerability in Cisco Unity Connection
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
4.8
2024-01-26 CVE-2024-22551 Cross-site Scripting vulnerability in Ushainformatique Whatacart 2.0.7
WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.
network
low complexity
ushainformatique CWE-79
6.1
2024-01-26 CVE-2024-23890 Cross-site Scripting vulnerability in Ajaysharma Cups Easy 1.0
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/itempopup.php, in the description parameter.
network
low complexity
ajaysharma CWE-79
6.1
2024-01-26 CVE-2024-23891 Cross-site Scripting vulnerability in Ajaysharma Cups Easy 1.0
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/itemcreate.php, in the itemid parameter.
network
low complexity
ajaysharma CWE-79
6.1
2024-01-26 CVE-2024-23892 Cross-site Scripting vulnerability in Ajaysharma Cups Easy 1.0
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/costcentercreate.php, in the costcenterid parameter.
network
low complexity
ajaysharma CWE-79
6.1
2024-01-26 CVE-2024-23893 Cross-site Scripting vulnerability in Ajaysharma Cups Easy 1.0
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/costcentermodify.php, in the costcenterid parameter.
network
low complexity
ajaysharma CWE-79
6.1
2024-01-26 CVE-2024-23894 Cross-site Scripting vulnerability in Ajaysharma Cups Easy 1.0
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stockissuancecreate.php, in the issuancedate parameter.
network
low complexity
ajaysharma CWE-79
6.1