Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-12-10 CVE-2024-11940 The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-12-10 CVE-2024-9672 Cross-site Scripting vulnerability in Papercut MF
A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF.
network
low complexity
papercut CWE-79
5.4
2024-12-09 CVE-2024-54935 Cross-site Scripting vulnerability in Lopalopa E-Learning Management System 1.0
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0.
network
low complexity
lopalopa CWE-79
5.4
2024-12-09 CVE-2024-54919 Cross-site Scripting vulnerability in Lopalopa E-Learning Management System 1.0
A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0.
network
low complexity
lopalopa CWE-79
5.4
2024-12-09 CVE-2024-54936 Cross-site Scripting vulnerability in Lopalopa E-Learning Management System 1.0
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0.
network
low complexity
lopalopa CWE-79
5.4
2024-12-09 CVE-2024-12359 Cross-site Scripting vulnerability in Code-Projects Admin Dashboard 1.0
A vulnerability was found in code-projects Admin Dashboard 1.0.
network
low complexity
code-projects CWE-79
5.4
2024-12-07 CVE-2024-47107 IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting.
network
low complexity
CWE-79
6.4
2024-12-07 CVE-2024-11380 The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortcode in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2024-12-07 CVE-2024-11457 The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2024-12-07 CVE-2024-11464 The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1