Vulnerabilities (CVE)

Filtered by CWE-79
Total 36697 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-13326 1 Ibuildapp 1 Ibuildapp 2025-05-07 N/A 6.1 MEDIUM
The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2025-45751 1 Senior-walter 1 Web-based Pharmacy Product Management System 2025-05-07 N/A 6.1 MEDIUM
SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.
CVE-2022-32407 1 Softr 1 Softr 2025-05-07 N/A 6.1 MEDIUM
Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New Account module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-13098 1 Megamindstechnologies 1 Wordpress Email Newsletter 2025-05-07 N/A 5.4 MEDIUM
The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13094 1 Wptriggers 1 Wp Triggers Lite 2025-05-07 N/A 7.1 HIGH
The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2025-1453 1 Zephyrwest 1 Category Posts Widget 2025-05-07 N/A 4.8 MEDIUM
The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-13056 1 Phycticio 1 Dyn Business Panel 2025-05-07 N/A 7.1 HIGH
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13055 1 Phycticio 1 Dyn Business Panel 2025-05-07 N/A 7.1 HIGH
The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13325 1 Croberts 1 Glossy 2025-05-07 N/A 6.1 MEDIUM
The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-13114 1 Phptechie 1 Wp Projects Portfolio With Client Testimonials 2025-05-07 N/A 6.1 MEDIUM
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13099 1 Apidaze 1 Widget4call 2025-05-07 N/A 5.4 MEDIUM
The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2025-0368 1 Karacsi Maci 1 Banner Garden 2025-05-07 N/A 6.1 MEDIUM
The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users.
CVE-2024-1743 1 Vanquish 1 Woocommerce Customers Manager 2025-05-07 N/A 5.9 MEDIUM
The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-13314 1 Techearty 1 Carousel\, Slider\, Gallery By Wp Carousel 2025-05-07 N/A 3.5 LOW
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-13329 1 Solidres 1 Solidres 2025-05-07 N/A 7.1 HIGH
The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-13327 1 Webdesignby 1 Musicbox 2025-05-07 N/A 6.1 MEDIUM
The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-13585 1 Wp-dreams 1 Ajax Search 2025-05-07 N/A 3.5 LOW
The Ajax Search Lite WordPress plugin before 4.12.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-12308 1 Logichunt 1 Logo Slider 2025-05-07 N/A 5.4 MEDIUM
The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2024-13605 1 10web 1 Form Maker 2025-05-07 N/A 4.8 MEDIUM
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-13822 1 Totalsuite 1 Totalcontest 2025-05-07 N/A 6.1 MEDIUM
The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.