Total
37390 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-33570 | 1 Postbird Project | 1 Postbird | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections. | |||||
CVE-2021-33562 | 1 Shopizer | 1 Shopizer | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL. | |||||
CVE-2021-33561 | 1 Shopizer | 1 Shopizer | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html. | |||||
CVE-2021-33557 | 1 Mantisbt | 1 Mantisbt | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field. | |||||
CVE-2021-33513 | 1 Plone | 1 Plone | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool. | |||||
CVE-2021-33512 | 1 Plone | 1 Plone | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document. | |||||
CVE-2021-33508 | 1 Plone | 1 Plone | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item. | |||||
CVE-2021-33507 | 2 Plone, Zope | 2 Plone, Zope | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS. | |||||
CVE-2021-33501 | 1 Overwolf | 1 Overwolf | 2024-11-21 | 9.3 HIGH | 9.6 CRITICAL |
Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL. | |||||
CVE-2021-33496 | 1 Dutchcoders | 1 Transfer.sh | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Dutchcoders transfer.sh before 1.2.4 allows XSS via an inline view. | |||||
CVE-2021-33495 | 1 Open-xchange | 1 Ox App Suite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
OX App Suite 7.10.5 allows XSS via an OX Chat system message. | |||||
CVE-2021-33494 | 1 Open-xchange | 1 Ox App Suite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering. | |||||
CVE-2021-33492 | 1 Open-xchange | 1 Ox App Suite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
OX App Suite 7.10.5 allows XSS via an OX Chat room name. | |||||
CVE-2021-33490 | 1 Open-xchange | 1 Ox App Suite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature. | |||||
CVE-2021-33489 | 1 Open-xchange | 1 Ox App Suite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file. | |||||
CVE-2021-33483 | 1 Onyaktech Comments Pro Project | 1 Onyaktech Comments Pro | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment. | |||||
CVE-2021-33469 | 1 Phpgurukul | 1 Covid19 Testing Management System | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter. | |||||
CVE-2021-33425 | 1 Openwrt | 1 Openwrt | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject arbitrary Javascript in the OpenWRT Hostname via the Hostname Change operation. | |||||
CVE-2021-33348 | 1 Jfinal | 1 Jfinal | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases. | |||||
CVE-2021-33347 | 1 Jpress | 1 Jpress | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag management module. If you log in to the background by means of weak password, the storage XSS vulnerability can occur. |