Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-04 | CVE-2024-9368 | Cross-site Scripting vulnerability in Miguelmello Aggregator Advanced Settings The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. | 5.4 |
2024-10-04 | CVE-2024-9372 | Cross-site Scripting vulnerability in Wpblockshub WP Blocks HUB The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. | 5.4 |
2024-10-04 | CVE-2024-9375 | Cross-site Scripting vulnerability in Techbanker Captcha Bank The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.0.36. | 6.1 |
2024-10-04 | CVE-2024-9384 | Cross-site Scripting vulnerability in Wpfactory Quantity Dynamic Pricing & Bulk Discounts for Woocommerce The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.8.0. | 6.1 |
2024-10-04 | CVE-2024-9421 | Cross-site Scripting vulnerability in Prontotools Login Logout Shortcode The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-10-04 | CVE-2024-9445 | Cross-site Scripting vulnerability in Acekyd Display Medium Posts The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medium_posts shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-10-03 | CVE-2024-41587 | Cross-site Scripting vulnerability in Draytek products Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6. | 5.4 |
2024-10-03 | CVE-2024-41591 | Cross-site Scripting vulnerability in Draytek products DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS. | 6.1 |
2024-10-03 | CVE-2024-47617 | Cross-site Scripting vulnerability in Sulu 2.5.20/2.6.4 Sulu is a PHP content management system. | 6.1 |
2024-10-03 | CVE-2024-47618 | Cross-site Scripting vulnerability in Sulu Sulu is a PHP content management system. | 5.4 |