Vulnerabilities (CVE)

Filtered by CWE-80
Total 251 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36057 1 Discourse 1 Discourse-chat 2022-09-09 N/A 4.8 MEDIUM
Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse Chat can be affected by admin users inserting HTML into chat titles and descriptions, causing a Cross-Site Scripting (XSS) attack. Version 0.9 contains a patch for this issue.
CVE-2021-43862 1 Jquery.terminal Project 1 Jquery.terminal 2022-08-09 2.1 LOW 5.4 MEDIUM
jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31.1 contain a low impact and limited cross-site scripting (XSS) vulnerability. The code for XSS payload is always visible, but an attacker can use other techniques to hide the code the victim sees. If the application uses the `execHash` option and executes code from URL, the attacker can use this URL to execute their code. The scope is limited because the javascript attribute used is added to span tag, so no automatic execution like with `onerror` on images is possible. This issue is fixed in version 2.31.1. As a workaround, the user can use formatting that wrap whole user input and its no op. The code for this workaround is available in the GitHub Security Advisory. The fix will only work when user of the library is not using different formatters (e.g. to highlight code in different way).
CVE-2022-1293 1 Thalesgroup 1 Citadel 2022-08-08 N/A 6.1 MEDIUM
The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions.
CVE-2021-39348 1 Thimpress 1 Learnpress 2022-08-05 3.5 LOW 4.8 MEDIUM
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.3.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. Please note that this is seperate from CVE-2021-24702.
CVE-2017-20140 1 Ambit 1 Movie Portal Script 2022-07-29 N/A 6.1 MEDIUM
A vulnerability was found in Itech Movie Portal Script 7.36. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /movie.php. The manipulation of the argument f with the input <img src=i onerror=prompt(1)> leads to basic cross site scripting (Reflected). The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2020-13564 2 Open-emr, Phpgacl Project 2 Openemr, Phpgacl 2022-07-29 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template acl_id parameter.
CVE-2020-13563 2 Open-emr, Phpgacl Project 2 Openemr, Phpgacl 2022-07-29 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template group_id parameter.
CVE-2022-29168 1 Wire 1 Wire-webapp 2022-07-11 4.3 MEDIUM 6.1 MEDIUM
Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient escaping when rendering `@mentions` in the wire-webapp. If a user receives and views a malicious message, arbitrary code is injected and executed in the context of the victim allowing the attacker to fully control the user account. Wire-desktop clients that are connected to a vulnerable wire-webapp version are also vulnerable to this attack. The issue has been fixed in wire-webapp 2022-05-04-production.0 and is already deployed on all Wire managed services. On-premise instances of wire-webapp need to be updated to docker tag 2022-05-04-production.0-v0.29.7-0-a6f2ded or wire-server 2022-05-04 (chart/4.11.0) or later. No known workarounds exist.
CVE-2017-20122 1 Bitrix24 1 Bitrix Site Manager 2022-07-09 3.5 LOW 5.4 MEDIUM
A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(’p').text(’Hacked’)" /> leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2017-20108 1 Easy Table Project 1 Easy Table 2022-07-07 3.5 LOW 5.4 MEDIUM
A vulnerability classified as problematic has been found in Easy Table Plugin 1.6. This affects an unknown part of the file /wordpress/wp-admin/options-general.php. The manipulation with the input "><script>alert(1)</script> leads to basic cross site scripting. It is possible to initiate the attack remotely.
CVE-2017-20098 1 Weblizar 1 Admin Custom Login 2022-07-06 3.5 LOW 4.8 MEDIUM
A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely.
CVE-2017-20100 1 Air Transfer Project 1 Air Transfer 2022-07-06 4.3 MEDIUM 6.1 MEDIUM
A vulnerability was found in Air Transfer 1.0.14/1.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2017-20092 1 Yoast 1 Google Analytics Dashboard 2022-06-30 4.3 MEDIUM 6.1 MEDIUM
A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.
CVE-2017-20094 1 Newstatpress Project 1 Newstatpress 2022-06-30 3.5 LOW 5.4 MEDIUM
A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack may be initiated remotely. Upgrading to version 1.2.5 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20097 1 Wp-filebase Download Manager Project 1 Wp-filebase Download Manager 2022-06-30 4.3 MEDIUM 6.1 MEDIUM
A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.
CVE-2017-20096 1 Wp-spamfree Anti-spam Project 1 Wp-spamfree Anti-spam 2022-06-30 4.3 MEDIUM 6.1 MEDIUM
A vulnerability classified as problematic has been found in WP-SpamFree Anti-Spam Plugin 2.1.1.4. This affects an unknown part. The manipulation leads to basic cross site scripting. It is possible to initiate the attack remotely.
CVE-2017-20089 1 Gwolle Guestbook Project 1 Gwolle Guestbook 2022-06-29 4.3 MEDIUM 6.1 MEDIUM
A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated remotely.
CVE-2020-13562 2 Open-emr, Phpgacl Project 2 Openemr, Phpgacl 2022-06-29 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.
CVE-2017-20087 1 Thealpinepress 1 Alpine-photo-tile-for-instagram 2022-06-29 4.3 MEDIUM 6.1 MEDIUM
A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.
CVE-2017-20085 1 Bytesforall 1 Atahualpa 2022-06-29 3.5 LOW 5.4 MEDIUM
A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.