Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-37905: [FIXED] xss issue · w8tcha/CKEditor-WordCount-Plugin@0f03b3e

ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wordcount-plugin` plugin for CKEditor4 is susceptible to cross-site scripting when switching to the source code mode. This issue has been addressed in version 1.17.12 of the `ckeditor-wordcount-plugin` plugin and users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE
#xss#vulnerability
CVE-2023-25840: ArcGIS Server Security 2023 Update 1 Patch available!

There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.  The privileges required to execute this attack are high.

CVE-2023-37742: RiSec Advisories | WebBoss.io CMS XSS 2022 [1]

WebBoss.io CMS before v3.6.8.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

GHSA-78q2-cv3p-x9fm: Pimcore Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.

GHSA-vmpv-qjhq-r463: Pimcore Cross-site Scripting vulnerability

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-3821

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-3822: Fix Xss in the link Editable · pimcore/pimcore@d75888a

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.

CMS-Bank Mellat Payment Manager 1.0.0 Cross Site Scripting

CMS-Bank Mellat Payment Manager version 1.0.0 suffers from a cross site scripting vulnerability.

Foody Friend 1.0 Arbitrary File Upload / Cross Site Scripting

Foody Friend version 1.0 suffers from an arbitrary file upload vulnerability that can assist in cross site scripting attacks.