Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-10-07 CVE-2024-45153 Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
CWE-79
5.4
2024-10-05 CVE-2024-9528 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.
network
high complexity
CWE-79
4.9
2024-10-05 CVE-2024-9455 The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-05 CVE-2024-47840 Cross-site Scripting vulnerability in Wikimedia Apex
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.
network
low complexity
wikimedia CWE-79
4.8
2024-10-05 CVE-2024-47847 Cross-site Scripting vulnerability in Mediawiki Cargo 3.6.0
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
network
low complexity
mediawiki CWE-79
6.1
2024-10-04 CVE-2024-43686 Cross-site Scripting vulnerability in Microchip Timeprovider 4100 Firmware
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
network
low complexity
microchip CWE-79
6.1
2024-10-04 CVE-2024-43687 Cross-site Scripting vulnerability in Microchip Timeprovider 4100 Firmware
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
network
low complexity
microchip CWE-79
6.1
2024-10-04 CVE-2024-25691 Cross-site Scripting vulnerability in Esri Portal for Arcgis 10.8.1/10.9.1/11.1
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1, 10.9.1 and 10.8.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
6.1
2024-10-04 CVE-2024-25694 Cross-site Scripting vulnerability in Esri Portal for Arcgis 10.8.1/10.9/10.9.1
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 10.8.1 – 10.9.1 that may allow a remote, authenticated attacker to create a crafted link that is stored in the Layer Showcase application configuration which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
4.8
2024-10-04 CVE-2024-25701 Cross-site Scripting vulnerability in Esri Portal for Arcgis
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Experience Builder versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link that is stored in the Experience Builder Embed widget which when loaded could potentially execute arbitrary JavaScript code in the victim’s browser.
network
low complexity
esri CWE-79
4.8