Vulnerabilities (CVE)

Filtered by CWE-79
Total 36049 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-12587 1 Edmonparker 1 Contact Form Master 2025-05-17 N/A 6.1 MEDIUM
The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-12715 1 Outself 1 Asgard Security Scanner 2025-05-17 N/A 6.1 MEDIUM
The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-12714 1 Syedfakharabbas 1 Backlink Monitoring Manager 2025-05-17 N/A 6.1 MEDIUM
The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-10568 1 Wp-dreams 1 Ajax Search 2025-05-17 N/A 4.7 MEDIUM
The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-10518 1 Properfraction 1 Profilepress 2025-05-17 N/A 4.8 MEDIUM
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Membership Plan settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-10517 1 Properfraction 1 Profilepress 2025-05-17 N/A 4.8 MEDIUM
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-11841 1 Jordangillman 1 Tithe.ly Giving Button 2025-05-17 N/A 5.4 MEDIUM
The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2024-7313 1 Getshieldsecurity 1 Shield Security 2025-05-17 N/A 6.1 MEDIUM
The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-6879 1 Expresstech 1 Quiz And Survey Master 2025-05-17 N/A 4.7 MEDIUM
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.
CVE-2024-3282 1 Wptablebuilder 1 Wp Table Builder 2025-05-17 N/A 4.8 MEDIUM
The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-11107 1 Bowo 1 System Dashboard 2025-05-17 N/A 6.1 MEDIUM
The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
CVE-2024-10893 1 Wpbookingcalendar 1 Wp Booking Calendar 2025-05-17 N/A 4.8 MEDIUM
The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-9934 1 Aueda 1 Wp-imagezoom 2025-05-17 N/A 6.1 MEDIUM
The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-10000 1 Masteriyo 1 Masteriyo 2025-05-17 N/A 6.4 MEDIUM
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with student-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-5429 1 Logichunt 1 Logo Slider 2025-05-17 N/A 7.6 HIGH
The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2023-3726 1 Ocsinventory-ng 1 Ocsinventory-ocsreports 2025-05-16 N/A 6.9 MEDIUM
OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.
CVE-2024-44041 1 Northernbeacheswebsites 1 Ideapush 2025-05-16 N/A 5.9 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.66.
CVE-2024-47638 1 Vcita 1 Online Booking \& Scheduling Calendar For Wordpress By Vcita 2025-05-16 N/A 7.1 HIGH
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.6.
CVE-2024-7891 1 Just-a-web-developer 1 Floating Contact Button 2025-05-16 N/A 4.8 MEDIUM
The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2024-7955 1 Squirrly 1 Starbox 2025-05-16 N/A 4.8 MEDIUM
The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).