VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2143 CVEsRSS

CVE-2024-6886Critical· 10.0PoC
2y ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

▾ AbyssalGitea · Gitea Open Source Git ServerEPSS 33%via NVD
CVE-2024-43113Medium· 6.1
2y ago

The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

▾ Sunlitmozilla · firefox_mobileEPSS 0.25%via NVD
CVE-2024-43112Medium· 6.1
2y ago

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

▾ Sunlitmozilla · firefox_mobileEPSS 0.25%via NVD
CVE-2024-43111Medium· 6.1
2y ago

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

▾ Sunlitmozilla · firefox_mobileEPSS 0.27%via NVD
CVE-2024-35768Medium· 5.9
2y ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Co…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Co…

▾ Sunlitblueastral · page_builder:_live_composerEPSS 0.32%via NVD
CVE-2023-7259Low· 2.4
2y ago

** DISPUTED ** A vulnerability was found in zzdevelop lenosp up to 20230831

** DISPUTED ** A vulnerability was found in zzdevelop lenosp up to 20230831. It has been classified as problematic. This affects an unknown part of the component Adduser Page. The manipulation of the argument username with the input <scr…

▾ SunlitEPSS 0.34%via NVD
CVE-2024-3822Medium· 4.8PoC
2y ago

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a…

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such a…

▾ Twilightmranderson · base64_encoder/decoderEPSS 0.75%via NVD
CVE-2024-31828Medium· 6.1
2y ago

Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

▾ Sunlitlavalite · lavaliteEPSS 0.50%via NVD
CVE-2023-6717Medium· 6.0
2y ago

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This is…

▾ SunlitRed Hat · keycloakEPSS 0.70%via NVD
CVE-2024-1282Medium· 6.4
2y ago

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficient input sanitizat…

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficient input sanitizat…

▾ Sunlitonlineoptimisation · email_encoderEPSS 0.44%via NVD
CVE-2023-6123High· 7.5
2y ago

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

▾ Twilightopentext · alm_octaneEPSS 0.51%via NVD
CVE-2024-0758Medium· 6.1
2y ago

MolecularFaces before 0.3.0 is vulnerable to cross site scripting

MolecularFaces before 0.3.0 is vulnerable to cross site scripting. A remote attacker can execute arbitrary JavaScript in the context of a victim browser via crafted molfiles.

▾ Sunlitipb-halle · molecularfacesEPSS 0.57%via NVD
CVE-2023-7070Medium· 6.4
2y ago

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in all versions up to, and including, 2.1.9 due to insufficient input s…

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in all versions up to, and including, 2.1.9 due to insufficient input s…

▾ Sunlitonlineoptimisation · email_encoderEPSS 0.40%via NVD
CVE-2024-22195Medium· 5.4
2y ago

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

▾ Sunlitjinja2 · jinja2EPSS 0.89%via OSV
CVE-2024-22048Medium· 6.1
2y ago

govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability

govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.

▾ Sunlitgov.uk · govuk_tech_docsEPSS 0.50%via NVD
CVE-2024-21911Medium· 6.1
2y ago

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's bro…

▾ Sunlittiny · tinymceEPSS 1.2%via NVD
CVE-2024-21908Medium· 6.1
2y ago

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's bro…

▾ Sunlittiny · tinymceEPSS 1.1%via NVD
CVE-2023-6134Medium· 4.6
2y ago

A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token

A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (X…

▾ Sunlitredhat · single_sign-onEPSS 1.3%via NVD
CVE-2023-6710Medium· 5.4PoC
2y ago

A flaw was found in the mod_proxy_cluster in the Apache server

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script …

▾ Twilightmodcluster · mod_proxy_clusterEPSS 2.2%via NVD
CVE-2023-49926Medium· 6.1
2y ago

app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

▾ Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2023-47821Medium· 6.5
2y ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jannis Thuemmig Email Encoder plugin <= 2.1.8 versions.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jannis Thuemmig Email Encoder plugin <= 2.1.8 versions.

▾ Sunlitonlineoptimisation · email_encoderEPSS 0.42%via NVD
CVE-2023-46734Medium· 6.1
2y ago

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_sa…

▾ Sunlitsensiolabs · symfonyEPSS 0.69%via NVD
CVE-2023-5758Medium· 6.1
2y ago

When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack

When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.

▾ Sunlitmozilla · firefox_mobileEPSS 0.43%via NVD
CVE-2023-45815Medium· 6.4
2y ago

ArchiveBox is an open source self-hosted web archiving system

ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you are logged in to the ArchiveBox admin site in the same b…

▾ Sunlitarchivebox · archiveboxEPSS 0.68%via NVD
CVE-2023-5578Low· 3.5
2y ago

A vulnerability was detected in Portábilis i-Educar up to 2.7.5

A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the in…

▾ Sunlitportabilis · i-educarEPSS 0.42%via NVD
CVE-2023-4547Low· 3.5PoC
3y ago

A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3

A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible…

▾ Twilightspa-cart · ecommerce_cmsEPSS 60%via NVD
CVE-2023-41098Medium· 6.1
3y ago

An issue was discovered in MISP 2.4.174

An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.

▾ Sunlitmisp-project · mispEPSS 0.42%via NVD
CVE-2023-40224Medium· 6.1
3y ago

MISP 2.4.174 allows XSS in app/View/Events/index.ctp.

MISP 2.4.174 allows XSS in app/View/Events/index.ctp.

▾ Sunlitmisp-project · mispEPSS 0.43%via NVD
CVE-2023-3384Medium· 5.4
3y ago

A flaw was found in the Quay registry

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an imag…

▾ Sunlitredhat · quayEPSS 0.48%via NVD
CVE-2023-37307Medium· 5.4
3y ago

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

▾ Sunlitmisp-project · mispEPSS 0.50%via NVD
CWE-79 vulnerabilities (CVEs) — page 64 · VulnSea