Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-36289

An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.

CVE
#xss#vulnerability#web#auth
CVE-2023-36288

An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.

PHPJabbers Forum Script 3.0 Persistent Cross Site Scripting

PHPJabbers Forum Script version 3.0 suffers from a persistent cross site scripting vulnerability.

PHPJabbers Forum Script 3.0 Cross Site Scripting

PHPJabbers Forum Script version 3.0 suffers from a cross site scripting vulnerability.

PHPJabbers STIVA Blog Script 4.1 Cross Site Scripting

PHPJabbers STIVA Blog Script version 4.1 suffers from a cross site scripting vulnerability.

Adiscon LogAnalyzer 4.1.5 Cross Site Scripting

Adiscon LogAnalyzer version 4.1.5 suffers from a cross site scripting vulnerability.

PHPJabbers Knowledge Base Builder 3.0 Cross Site Scripting

PHPJabbers Knowledge Base Builder version 3.0 suffers from a cross site scripting vulnerability.

CVE-2023-29100: WordPress The7 theme <= 11.6.0 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dream-Theme The7 plugin <= 11.6.0 versions.

CVE-2023-28751: WordPress Wp Ultimate Review plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

CVE-2023-32580: WordPress Password Protected plugin <= 2.6.2 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions.