Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2021-43707: XSS · Issue #18 · maccmspro/maccms10

Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

CVE
#xss#vulnerability#mac#git
CVE-2021-42946: CVE-2021-42946: HTMLy 2.8.1 XSS vulnerability

A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.

CVE-2021-42869: CVE-2021-42869: Chikitsa 2.0.2 XSS vulnerability

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.

CVE-2021-42867: CVE-2021-42967: HTMLy 2.8.1 XSS vulnerability

A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages.

CVE-2021-42868: CVE-2021-42868: Chikitsa 2.0.2 XSS vulnerability

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. .

CVE-2021-42866: CVE-2021-42866: Pixelimity 1.0 XSS vulnerability

A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php

CVE-2021-43505

Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

CVE-2022-0350: :arrow_up: · Vanessa219/vditor@e912e36

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

CVE-2022-0350: :arrow_up: · Vanessa219/vditor@e912e36

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

CVE-2022-24299

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.