Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-27436

A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.

CVE
#xss#vulnerability#web
CVE-2022-28062: CVEs/POC.md at main · D4rkP0w4r/CVEs

Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code.

CVE-2022-28379: Release v2.9.17 · NginxProxyManager/nginx-proxy-manager

jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.

CVE-2022-28368: GitHub - snyk-labs/php-goof: Snyk PHP Goof - A vulnerable PHP demo application

Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).

CVE-2022-21830

A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.

CVE-2021-32503: The SICK Product Security Incident Response Team (SICK PSIRT)

Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.

CVE-2022-26565: Security Issue - Cross Site Scripting (Stored) · Issue #35 · totaljs/cms

A cross-site scripting (XSS) vulnerability in Totaljs commit 95f54a5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.

GitLab addresses critical account hijack bug

Monthly release also addresses pair of stored XSS flaws

CVE-2022-24181: Add support for limiting allowed hosts · Issue #7649 · pkp/pkp-lib

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.