Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-01-08 CVE-2023-52196 Cross-site Scripting vulnerability in Ewels CPT Bootstrap Carousel
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: from n/a through 1.12.
network
low complexity
ewels CWE-79
6.1
2024-01-08 CVE-2023-51246 Cross-site Scripting vulnerability in Get-Simple Getsimplecms 3.3.16
A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.
network
low complexity
get-simple CWE-79
5.4
2024-01-08 CVE-2023-52203 Cross-site Scripting vulnerability in Cformsii Project Cformsii
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5.
network
low complexity
cformsii-project CWE-79
4.8
2024-01-08 CVE-2023-5911 Cross-site Scripting vulnerability in Hamidrezasepehr WP Custom Cursors | Wordpress Cursor Plugin 3.2
The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
hamidrezasepehr CWE-79
4.8
2024-01-08 CVE-2023-6141 Cross-site Scripting vulnerability in G5Plus Essential Real Estate
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.
network
low complexity
g5plus CWE-79
5.4
2024-01-08 CVE-2023-6161 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
themeum CWE-79
6.1
2024-01-08 CVE-2023-6529 Cross-site Scripting vulnerability in Rextheme WP VR
The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.
network
low complexity
rextheme CWE-79
6.1
2024-01-08 CVE-2023-6555 Cross-site Scripting vulnerability in I13Websolution Email Subscription Popup
The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
i13websolution CWE-79
6.1
2024-01-08 CVE-2023-6627 Cross-site Scripting vulnerability in Codecabin WP GO Maps
The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.
network
low complexity
codecabin CWE-79
6.1
2024-01-08 CVE-2023-29049 Cross-site Scripting vulnerability in Open-Xchange OX APP Suite 7.10.5/7.10.6
The "upsell" widget at the portal page could be abused to inject arbitrary script code.
network
low complexity
open-xchange CWE-79
6.1