Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-10-27 CVE-2024-10419 Cross-site Scripting vulnerability in Fabianros Blood Bank Management System 1.0
A vulnerability was found in code-projects Blood Bank Management System 1.0.
network
low complexity
fabianros CWE-79
6.1
2024-10-27 CVE-2024-10414 Cross-site Scripting vulnerability in PHPgurukul Vehicle Record System 1.0
A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0.
network
low complexity
phpgurukul CWE-79
4.8
2024-10-27 CVE-2024-10412 Cross-site Scripting vulnerability in Poco-Z Guns-Medial 1.0
A vulnerability was found in Poco-z Guns-Medical 1.0.
network
low complexity
poco-z CWE-79
5.4
2024-10-26 CVE-2024-10117 The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate shortcode in all versions up to, and including, 2.1.11 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-9642 The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-9853 The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-9456 The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.0 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-8870 The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.6.
network
low complexity
CWE-79
6.1
2024-10-26 CVE-2024-10091 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2024-10-26 CVE-2024-9454 The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.11 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4