Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-11-26 CVE-2024-11418 The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shipping_method_filter' parameter in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2024-11-26 CVE-2024-11677 Cross-site Scripting vulnerability in Hospital Management System Project Hospital Management System 1.0
A vulnerability was found in CodeAstro Hospital Management System 1.0.
5.4
2024-11-26 CVE-2024-11678 Cross-site Scripting vulnerability in Hospital Management System Project Hospital Management System 1.0
A vulnerability was found in CodeAstro Hospital Management System 1.0.
5.4
2024-11-26 CVE-2024-11675 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 1.0
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic.
network
low complexity
phpgurukul CWE-79
5.4
2024-11-26 CVE-2024-11676 Cross-site Scripting vulnerability in Hospital Management System Project Hospital Management System 1.0
A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic.
5.4
2024-11-25 CVE-2023-45181 Cross-site Scripting vulnerability in IBM Jazz Foundation
IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2024-11-25 CVE-2024-11660 Cross-site Scripting vulnerability in Anisha Farmacia 1.0
A vulnerability was found in code-projects Farmacia 1.0.
network
low complexity
anisha CWE-79
5.4
2024-11-23 CVE-2024-11228 The ????? ?? ???? – ???? ?? ???? plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pafw_instant_payment shortcode in all versions up to, and including, 5.1.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2024-11-23 CVE-2024-11229 The ???? ??? plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add_plus_talk shortcodes in all versions up to, and including, 1.1.18 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2024-11-23 CVE-2024-11231 The ???? ????? plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4