Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-34148: WordPress Backup Guard plugin <= 1.6.9.0 - Auth. Stored Cross-Site Scripting (XSS) vulnerability - Patchstack

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions.

CVE
#xss#vulnerability#web#wordpress#auth
CVE-2023-0322

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS.This issue affects UNIS: before 28376.

CVE-2023-24891

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVE-2023-24921

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVE-2023-24920

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVE-2023-24919

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVE-2023-24879

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVE-2023-27070: [Security] Stored XSS in platform name · Issue #53 · totaljs/openplatform

A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field.

CVE-2023-27069: [Security] Stored XSS in account name · Issue #52 · totaljs/openplatform

A stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the account name field.

CVE-2023-1395: SourceCodester Yoga Class Registration System list.php cross site scripting_Dwayne_Wade的博客-CSDN博客

A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. It has been declared as problematic. This vulnerability affects the function query of the file admin/user/list.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-222982 is the identifier assigned to this vulnerability.