Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-08 | CVE-2023-52196 | Cross-site Scripting vulnerability in Ewels CPT Bootstrap Carousel Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: from n/a through 1.12. | 6.1 |
2024-01-08 | CVE-2023-51246 | Cross-site Scripting vulnerability in Get-Simple Getsimplecms 3.3.16 A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page. | 5.4 |
2024-01-08 | CVE-2023-52203 | Cross-site Scripting vulnerability in Cformsii Project Cformsii Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5. | 4.8 |
2024-01-08 | CVE-2023-5911 | Cross-site Scripting vulnerability in Hamidrezasepehr WP Custom Cursors | Wordpress Cursor Plugin 3.2 The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 4.8 |
2024-01-08 | CVE-2023-6141 | Cross-site Scripting vulnerability in G5Plus Essential Real Estate The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks. | 5.4 |
2024-01-08 | CVE-2023-6161 | Cross-site Scripting vulnerability in Themeum WP Crowdfunding The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |
2024-01-08 | CVE-2023-6529 | Cross-site Scripting vulnerability in Rextheme WP VR The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities. | 6.1 |
2024-01-08 | CVE-2023-6555 | Cross-site Scripting vulnerability in I13Websolution Email Subscription Popup The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |
2024-01-08 | CVE-2023-6627 | Cross-site Scripting vulnerability in Codecabin WP GO Maps The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site. | 6.1 |
2024-01-08 | CVE-2023-29049 | Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6 The "upsell" widget at the portal page could be abused to inject arbitrary script code. | 6.1 |